social-content
Pass
Audited by Gen Agent Trust Hub on Jul 28, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill features an 'Indirect Prompt Injection' surface within its 'Reverse Engineering Viral Content' framework. This section instructs the agent to ingest and analyze extensive datasets (500-1000+ posts) scraped from external social media platforms using third-party tools. If an attacker embeds malicious instructions within these public posts (e.g., in the text or metadata), they could potentially influence the agent's behavior during the analysis phase.
- Ingestion points: Untrusted social media post content collected via scrapers (documented in SKILL.md).
- Boundary markers: The instructions lack specific delimiters or 'ignore embedded instructions' warnings for the data processing phase.
- Capability inventory: The skill is designed to influence content generation and strategy based on the analyzed data.
- Sanitization: There are no instructions for sanitizing, escaping, or validating the external content before it is processed by the agent.
Audit Metadata