social-strategist

Pass

Audited by Gen Agent Trust Hub on Mar 29, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill documentation lists 'bash', 'git', and 'File ops' as available tools. While no specific malicious commands are present, the documentation refers to the ability to execute shell commands and modify files, which increases the potential impact if the agent is compromised by malicious input.
  • [PROMPT_INJECTION]: The skill is designed to ingest data from external sources and collaborate with other agents, creating a surface for indirect prompt injection.
  • Ingestion points: Processes handoffs from 'Content Creator', 'Trend Researcher', and 'Brand Guardian' (SKILL.md).
  • Boundary markers: No explicit boundary markers or instructions to ignore embedded commands in input data were found.
  • Capability inventory: The skill notes access to 'bash', 'git', and 'File ops' (SKILL.md).
  • Sanitization: No input sanitization or validation logic is defined to protect against instructions embedded in ingested data.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 29, 2026, 02:51 PM
Security Audit — agent-trust-hub — social-strategist