ID8Labs Agent Suite
Pass
Audited by Gen Agent Trust Hub on Apr 16, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill suite utilizes several well-known third-party platforms and MCP services to perform its core functions. These include Supabase for data management and authentication, Vercel for web hosting and analytics, and specialized tools like ElevenLabs and KLING AI for multimedia production.\n- [PROMPT_INJECTION]: The suite is vulnerable to indirect prompt injection due to its automated data ingestion workflows. Agents are instructed to scrape external websites (via Firecrawl) and community forums such as Reddit and Twitter/X (via Perplexity) to gather market intelligence and competitor signals. The instructions lack explicit boundary markers or validation steps to distinguish between ingested data and agent instructions, potentially allowing maliciously crafted content on those external platforms to influence the agent's behavior during analysis.
Audit Metadata