social-publisher

Pass

Audited by Gen Agent Trust Hub on Jul 8, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: Indirect Prompt Injection Surface. The skill is designed to trigger when new files are created in Google Drive and uses the filename directly in prompts for generating captions across multiple platforms. If a file is maliciously named to include instructions, the model might follow them instead of generating a caption.
  • Ingestion points: SKILL.md (n8n configuration trigger for google_drive files).
  • Boundary markers: Absent. The {filename} variable is interpolated into prompts without delimiters or warnings to ignore instructions within the data.
  • Capability inventory: The skill possesses high-impact capabilities including publishing content to TikTok, Instagram, YouTube, LinkedIn, and Twitter via its MCP server tools.
  • Sanitization: Absent. There is no evidence of filtering or validation for the filenames before they are processed by the LLM.
  • [SAFE]: The skill's architecture for multi-platform publishing and analytics tracking is consistent with standard marketing automation practices. It uses specialized tools defined within its own MCP server and does not include any suspicious external network calls or unauthorized credential access.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 8, 2026, 07:46 PM
Security Audit — agent-trust-hub — social-publisher