instagram-api
Pass
Audited by Gen Agent Trust Hub on Aug 6, 2026
Risk Level: SAFECOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill provides standard Python and shell (curl) examples for calling Meta's Graph API endpoints. These are restricted to the intended functionality of publishing and reading media.\n- [COMMAND_EXECUTION]: Includes a local utility script
scripts/verify.shdesigned to lint generated artifacts. The script operates offline and performs regex-based checks for API version pinning and metric correctness.\n- [DATA_EXFILTRATION]: Interacts withgraph.facebook.comandgraph.instagram.com(well-known services) to manage media and fetch insights. The skill requires providing a public URL for video uploads, which is a standard requirement for the Instagram Graph API.\n- [SAFE]: Documentation explicitly instructs the agent to read sensitive tokens from environment variables rather than hardcoding them into generated code.\n- [PROMPT_INJECTION]: The skill facilitates the ingestion of external data from Instagram into local documentation, creating an indirect prompt injection surface.\n - Ingestion points: Data enters through API calls to Meta's Graph API endpoints as described in
SKILL.md.\n - Boundary markers: The skill uses YAML frontmatter delimiters in the wiki artifacts as described in
references/insights-metrics.md.\n - Capability inventory: The agent uses
curl, the Pythonrequestslibrary, and file system writes to02-DOCS/wiki/shortform/.\n - Sanitization: No explicit sanitization or filtering is defined for retrieved captions or permalinks before ingestion.
Audit Metadata