productclank-campaigns

Pass

Audited by Gen Agent Trust Hub on Sep 24, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill allows users to provide custom instructions that influence AI-generated social media content, creating a vulnerability surface for indirect prompt injection.\n
  • Ingestion points: Campaign parameters like reply_guidelines and search_context in SKILL.md and references/API_REFERENCE.md accept free-text user input.\n
  • Boundary markers: The skill contains a specific 'Safety Note' advising that these fields should be treated as untrusted and strictly scoped to tone and style.\n
  • Capability inventory: The skill performs network operations to the ProductClank API and can initiate blockchain transactions using provided wallet clients.\n
  • Sanitization: The documentation states the server-side generation is sandboxed to isolate the effect of user-provided instructions.\n- [EXTERNAL_DOWNLOADS]: The skill documentation and helper scripts utilize external libraries for network and blockchain functionality.\n
  • Evidence: References to @x402/fetch, viem, and ethers are present in references/EXAMPLES.md and scripts/create-campaign.mjs.\n
  • Evidence: The skill refers to an external CLI tool repository on GitHub for campaign execution.\n- [COMMAND_EXECUTION]: Documentation includes instructions for using a command-line utility (communiply) to interact with the service and manage social media engagement.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 24, 2026, 04:45 AM
Security Audit — agent-trust-hub — productclank-campaigns