social-publisher
Pass
Audited by Gen Agent Trust Hub on Sep 1, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill requires the installation of the SocialClaw CLI tool from the public npm registry. Evidence: The setup instructions include
npm install -g socialclaw@0.1.12. - [INDIRECT_PROMPT_INJECTION]: The skill processes content for social media publication, creating a potential surface for indirect prompt injection if the source data is untrusted. 1. Ingestion points: Content defined in the
textfield ofschedule.json. 2. Boundary markers: Absent; there are no explicit delimiters to segregate post content from instructions. 3. Capability inventory: The agent can execute shell commands and perform network operations via thesocialclawCLI tool. 4. Sanitization: None; the skill relies on the underlying CLI tool and service for content processing.
Audit Metadata