content-factory-operator

Pass

Audited by Gen Agent Trust Hub on Jun 17, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: No malicious logic, obfuscation, or persistence mechanisms were detected. The skill's stated purpose aligns with its implementation as a content strategy and operations architect.
  • [PROMPT_INJECTION]: No direct prompt injection or safety bypass patterns were found. The skill does process external data such as transcripts and URLs (ingestion points identified in SKILL.md under Factory Inputs) and utilizes platform tools like create_post (capability inventory), which presents a surface for indirect prompt injection. However, no boundary markers or sanitization logic were observed, which is typical for content generation skills in this environment.
  • [DATA_EXFILTRATION]: The skill does not access sensitive local files or hardcoded credentials. No network operations targeting non-whitelisted or suspicious domains were identified.
  • [REMOTE_CODE_EXECUTION]: No runtime remote code execution patterns, such as piped shell commands or dynamic script generation from untrusted sources, were found.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 17, 2026, 12:40 PM
Security Audit — agent-trust-hub — content-factory-operator