social-media-finder-skill

Pass

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill retrieves and processes unstructured data from external social media platforms, which serves as a potential surface for indirect instructions.
  • Ingestion points: Data such as bio snippets and profile descriptions are fetched from social media platforms via the BrowserAct API in scripts/social_media_finder.py.
  • Boundary markers: The instructions do not specify the use of clear delimiters or warnings when the agent processes the retrieved profile data.
  • Capability inventory: The skill uses Python scripts to perform network operations and outputs data to the agent's context.
  • Sanitization: There is no evidence of filtering or sanitizing the content of the scraped social media descriptions before they are presented to the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 1, 2026, 11:51 AM
Security Audit — agent-trust-hub — social-media-finder-skill