last30days
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses the Bash tool to execute its own local Python orchestration script (
last30days.py) to manage the research pipeline, including parallel API requests and data normalization. - [EXTERNAL_DOWNLOADS]: The skill performs network operations to fetch research data from well-known services. It communicates with
api.openai.com(for Reddit discovery via the Responses API),api.x.ai(for X search), andwww.reddit.com(for thread enrichment). These downloads are necessary for the skill's primary function and target recognized service providers. - [INDIRECT_PROMPT_INJECTION]: The skill has a vulnerability surface for indirect prompt injection because it ingests untrusted text from social media and instructs the agent to synthesize this data into copy-paste-ready prompts for the user. Malicious content within social media posts could potentially influence the agent's output.
- Ingestion points: Untrusted social media text is retrieved through API responses in
scripts/lib/openai_reddit.py,scripts/lib/xai_x.py, andscripts/lib/reddit_enrich.py. - Boundary markers: The instructions in
SKILL.mdlack explicit delimiters or warnings to ignore instructions that might be embedded within the ingested social media content. - Capability inventory: The skill possesses significant capabilities, including
Bash,Read, andWritetool permissions, which could be relevant if a successful injection were to occur. - Sanitization: The skill does not implement specific sanitization or filtering to detect or strip instructions from the social media data before it is processed by the model for synthesis.
Audit Metadata