social-content

Pass

Audited by Gen Agent Trust Hub on Jul 28, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill features an 'Indirect Prompt Injection' surface within its 'Reverse Engineering Viral Content' framework. This section instructs the agent to ingest and analyze extensive datasets (500-1000+ posts) scraped from external social media platforms using third-party tools. If an attacker embeds malicious instructions within these public posts (e.g., in the text or metadata), they could potentially influence the agent's behavior during the analysis phase.
  • Ingestion points: Untrusted social media post content collected via scrapers (documented in SKILL.md).
  • Boundary markers: The instructions lack specific delimiters or 'ignore embedded instructions' warnings for the data processing phase.
  • Capability inventory: The skill is designed to influence content generation and strategy based on the analyzed data.
  • Sanitization: There are no instructions for sanitizing, escaping, or validating the external content before it is processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 28, 2026, 05:45 AM
Security Audit — agent-trust-hub — social-content