social-media-finder-skill
Pass
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill retrieves and processes unstructured data from external social media platforms, which serves as a potential surface for indirect instructions.
- Ingestion points: Data such as bio snippets and profile descriptions are fetched from social media platforms via the BrowserAct API in
scripts/social_media_finder.py. - Boundary markers: The instructions do not specify the use of clear delimiters or warnings when the agent processes the retrieved profile data.
- Capability inventory: The skill uses Python scripts to perform network operations and outputs data to the agent's context.
- Sanitization: There is no evidence of filtering or sanitizing the content of the scraped social media descriptions before they are presented to the agent.
Audit Metadata