social-media-strategy

Warn

Audited by Gen Agent Trust Hub on Aug 10, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill directs the agent to execute shell commands to probe the user's filesystem. It instructs the agent to run ls on several hidden directories within the home folder, including ~/.claude/skills/, ~/.agent/skills/, and ~/.agents/skills/, to detect other installed skills without explicit user request.
  • [EXTERNAL_DOWNLOADS]: The instructions recommend the installation of additional external skills from the AbsolutelySkilled repository using the npx skills add command. This represents the download and execution of remote code from a source that is not verified as a trusted organization or well-known service.
  • [PROMPT_INJECTION]: The skill includes a behavioral mandate requiring the agent to prefix its first response with a specific emoji (ᾞ2), overriding the standard interaction style. Additionally, the skill exposes a surface for indirect prompt injection by processing user-controlled content (social media post requests) without boundary markers or sanitization, while maintaining the capability to execute shell commands. Evidence: 1. Ingestion points: User-provided topics and post ideas for social media content. 2. Boundary markers: Absent. 3. Capability inventory: Filesystem inspection via shell commands (ls). 4. Sanitization: Absent.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 10, 2026, 02:07 PM
Security Audit — agent-trust-hub — social-media-strategy