ai-content-pipeline-automation
Pass
Audited by Gen Agent Trust Hub on Jun 25, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill requires cloning an external repository from GitHub (pennydinh/marketing-pineline-share) and running installation commands such as
npm installoryarn installto fetch dependencies. - [PROMPT_INJECTION]: An indirect prompt injection surface is present due to the skill's automated workflow.
- Ingestion points: The system crawls real-time data from external sources like Twitter, LinkedIn, and TechCrunch via the Research Module.
- Boundary markers: There are no defined boundary markers or instructions to the AI to ignore potential commands embedded in the crawled web content.
- Capability inventory: The skill generates text and video content which can then be automatically published to social media platforms (Facebook).
- Sanitization: No input sanitization or validation mechanisms are described for the data fetched from external sources before it is passed to the LLM (Claude/OpenAI).
Audit Metadata