sentiment-analyst
Pass
Audited by Gen Agent Trust Hub on Jun 13, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from external social platforms via the
derivatives_sentimenttool (action: 'reddit_trending'). There are no boundary markers or instructions to delimit this content or treat it as untrusted, creating an ingestion point for indirect prompt injection. While the skill primarily uses this data for report generation and lacks direct file-write or system-level capabilities, the absence of sanitization or explicit 'ignore instructions' warnings poses a minor risk. - [PROMPT_INJECTION]: The skill implements a 'Vendor Neutrality' policy that instructs the agent to systematically hide the identities of data sources and providers. This includes specific directions to suppress the names of external services in error messages (e.g., masking 'ApeWisdom' or 'Binance' with generic terms). These instructions force the agent to withhold specific diagnostic and source information from the user.
Audit Metadata