instagram-api

Pass

Audited by Gen Agent Trust Hub on Aug 6, 2026

Risk Level: SAFECOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides standard Python and shell (curl) examples for calling Meta's Graph API endpoints. These are restricted to the intended functionality of publishing and reading media.\n- [COMMAND_EXECUTION]: Includes a local utility script scripts/verify.sh designed to lint generated artifacts. The script operates offline and performs regex-based checks for API version pinning and metric correctness.\n- [DATA_EXFILTRATION]: Interacts with graph.facebook.com and graph.instagram.com (well-known services) to manage media and fetch insights. The skill requires providing a public URL for video uploads, which is a standard requirement for the Instagram Graph API.\n- [SAFE]: Documentation explicitly instructs the agent to read sensitive tokens from environment variables rather than hardcoding them into generated code.\n- [PROMPT_INJECTION]: The skill facilitates the ingestion of external data from Instagram into local documentation, creating an indirect prompt injection surface.\n
  • Ingestion points: Data enters through API calls to Meta's Graph API endpoints as described in SKILL.md.\n
  • Boundary markers: The skill uses YAML frontmatter delimiters in the wiki artifacts as described in references/insights-metrics.md.\n
  • Capability inventory: The agent uses curl, the Python requests library, and file system writes to 02-DOCS/wiki/shortform/.\n
  • Sanitization: No explicit sanitization or filtering is defined for retrieved captions or permalinks before ingestion.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 6, 2026, 09:37 PM
Security Audit — agent-trust-hub — instagram-api