social-playbook-skill

Pass

Audited by Gen Agent Trust Hub on Jun 24, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill consists of a SKILL.md file and a skill-report.json metadata file. Neither file contains executable code or dangerous system commands.
  • [DATA_EXPOSURE]: The skill references local database tables (social_playbooks, social_assets) and visual components for context, which is standard behavior for an agent skill working within a repository. No sensitive credentials or private keys are accessed or hardcoded.
  • [REMOTE_CODE_EXECUTION]: There are no patterns of remote code downloading or execution (e.g., no curl | bash, no package installations).
  • [INDIRECT_PROMPT_INJECTION]: While the skill processes marketing documents and client data, it is used for internal content generation. The capability set (Read, Write, Search) is appropriately scoped for its stated purpose of generating implementation-ready playbooks. The risk of indirect injection from processed docs is low given the descriptive nature of the output (scripts, captions, etc.).
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 24, 2026, 09:09 AM
Security Audit — agent-trust-hub — social-playbook-skill