social-hook

Pass

Audited by Gen Agent Trust Hub on Jul 19, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: The skill processes data from external local files (social-context.md or .agents/social-context.md) to define brand voice and audience constraints. This creates a surface for indirect prompt injection where instructions embedded in the context files could attempt to influence the agent's behavior. However, the skill lacks exploitable capabilities such as file writing, shell execution, or network access, which limits the potential impact of such an injection to the content of the generated text.
  • Ingestion points: social-context.md, .agents/social-context.md (read via local file access).
  • Boundary markers: Absent; the instructions do not specify delimiters or warnings for the content read from the context files.
  • Capability inventory: No dangerous capabilities detected; the skill performs only text generation and scoring.
  • Sanitization: Absent; content from context files is interpolated into the reasoning process without explicit filtering.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 19, 2026, 09:00 PM
Security Audit — agent-trust-hub — social-hook