Bookmarks
Pass
Audited by Gen Agent Trust Hub on Apr 20, 2026
Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
- [PROMPT_INJECTION]: The skill is designed to ingest untrusted data from external platforms including X, Reddit, and YouTube, creating a potential surface for indirect prompt injection. * Ingestion points: Bookmarks and saves from external social media platforms mentioned in SKILL.md. * Boundary markers: The skill does not define delimiters or provide instructions for the agent to ignore potentially malicious embedded content in the imported data. * Capability inventory: The agent is instructed to write files to the local '~/bookmarks/' directory and optionally generate summaries. * Sanitization: No sanitization, validation, or escaping of external content is described in the workflow.
- [NO_CODE]: The skill consists entirely of markdown instructions and metadata, containing no executable scripts, binaries, or automated code files.
Audit Metadata