last30days

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses the Bash tool to execute its own local Python orchestration script (last30days.py) to manage the research pipeline, including parallel API requests and data normalization.
  • [EXTERNAL_DOWNLOADS]: The skill performs network operations to fetch research data from well-known services. It communicates with api.openai.com (for Reddit discovery via the Responses API), api.x.ai (for X search), and www.reddit.com (for thread enrichment). These downloads are necessary for the skill's primary function and target recognized service providers.
  • [INDIRECT_PROMPT_INJECTION]: The skill has a vulnerability surface for indirect prompt injection because it ingests untrusted text from social media and instructs the agent to synthesize this data into copy-paste-ready prompts for the user. Malicious content within social media posts could potentially influence the agent's output.
  • Ingestion points: Untrusted social media text is retrieved through API responses in scripts/lib/openai_reddit.py, scripts/lib/xai_x.py, and scripts/lib/reddit_enrich.py.
  • Boundary markers: The instructions in SKILL.md lack explicit delimiters or warnings to ignore instructions that might be embedded within the ingested social media content.
  • Capability inventory: The skill possesses significant capabilities, including Bash, Read, and Write tool permissions, which could be relevant if a successful injection were to occur.
  • Sanitization: The skill does not implement specific sanitization or filtering to detect or strip instructions from the social media data before it is processed by the model for synthesis.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 07:20 AM
Security Audit — agent-trust-hub — last30days