signal-detection-pipeline

Pass

Audited by Gen Agent Trust Hub on Jul 20, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill acts as a high-level playbook coordinating other capabilities without introducing dangerous commands or hidden logic.
  • [PROMPT_INJECTION]: The skill has an attack surface for indirect prompt injection because it processes data from untrusted sources like Reddit and LinkedIn. However, this is part of its core functionality and no malicious injection content was found.
  • Ingestion points: SKILL.md (reddit-scraper, linkedin-post-research, job-posting-intent)
  • Boundary markers: Not explicitly mentioned in instructions.
  • Capability inventory: No local scripts; utilizes external capability skills for scraping and contact management.
  • Sanitization: None mentioned for processed external content.
  • [EXTERNAL_DOWNLOADS]: Installation uses the standard 'npx' command for the platform, which is considered a safe and intended practice.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 20, 2026, 06:25 PM
Security Audit — agent-trust-hub — signal-detection-pipeline