social-media-posts

Pass

Audited by Gen Agent Trust Hub on Jun 13, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill is an instruction-based utility for natural language generation. It contains no malicious code, remote script downloads, or unauthorized network operations.
  • [PROMPT_INJECTION]: The skill exhibits a surface for indirect prompt injection as it reads and processes external content (files or URLs) provided by the user to generate social media copy. Maliciously crafted source documents could contain instructions aimed at manipulating the agent's output.
  • Ingestion points: Processes source content from file paths or URLs provided by the user (SKILL.md).
  • Boundary markers: The instructions do not define clear delimiters or specify that the agent should ignore instructions embedded within the source content.
  • Capability inventory: The skill uses Read, Write, Glob, and Grep tools to handle file operations and content extraction.
  • Sanitization: There is no mention of sanitizing or validating external content before processing it for post generation.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 13, 2026, 08:44 AM
Security Audit — agent-trust-hub — social-media-posts