Publish to Social

Pass

Audited by Gen Agent Trust Hub on Aug 13, 2026

Risk Level: SAFE
Full Analysis
  • [DATA_EXFILTRATION]: The skill transmits video URLs and metadata to https://api.agent-media.ai and references media stored on Cloudflare R2 (r2.dev). These operations are essential for the skill's primary function of social media distribution and are routed through the vendor's own API services.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes user-supplied data for public social media publication, which creates a surface for potential misuse. 1. Ingestion points: Data provided to the social_publish tool, including caption and video_url (SKILL.md). 2. Boundary markers: None identified in the provided documentation to differentiate between instructions and user data. 3. Capability inventory: The skill provides functionality to publish content to external social media channels. 4. Sanitization: The documentation does not describe any sanitization or validation logic for social media captions, which could potentially be exploited to post unintended content if the agent is subjected to prompt injection.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 13, 2026, 05:36 PM
Security Audit — agent-trust-hub — Publish to Social