content-engine

Pass

Audited by Gen Agent Trust Hub on Jun 9, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [SAFE]: The skill architecture adheres to security best practices by implementing human-in-the-loop review (via Postiz drafts) and maintaining strict scoring gates for all generated assets. No hardcoded credentials or unauthorized data exfiltration patterns were found.
  • [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface as it ingests trending content and 'growth hack' scripts from external sources (Apify, creator threads). This is mitigated by explicit instructions to 'reject outright' malicious tactics (e.g., geo spoofing, account farming) and to 'abstract the structure, not the exact creator.' These guardrails ensure that external content is used for pattern recognition rather than direct execution of malicious instructions.
  • [COMMAND_EXECUTION]: Functional dynamic code generation is present in the form of HTML/CSS/GSAP compositions created for the HyperFrames rendering tool. This generation is legitimate, task-specific, and governed by design constraints provided in local workspace files (e.g., DESIGN.md), posing no risk of arbitrary command execution on the host system.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 9, 2026, 09:35 PM
Security Audit — agent-trust-hub — content-engine