social-publishing-weapon

Pass

Audited by Gen Agent Trust Hub on Jul 25, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides a robust framework for social media automation with a primary focus on safety. It includes 'Critical Directives' that mandate human oversight for all published content, effectively preventing unauthorized or accidental live posts.
  • [CREDENTIALS_UNSAFE]: The skill demonstrates secure handling of sensitive data. It explicitly directs the agent to resolve authentication tokens from environment variables rather than hardcoding them and provides an example configuration file with placeholders only. It further mandates that tokens must never be logged or committed to version control.
  • [EXTERNAL_DOWNLOADS]: All external references and URLs within the skill point to legitimate documentation, research sources, and service providers (e.g., GoHighLevel, Zernio, Stripe, and Ayrshare) consistent with the skill's purpose. No suspicious downloads or remote script execution patterns were found.
  • [PROMPT_INJECTION]: The skill implements a 'drafts-only' primitive as a security boundary. By ensuring all content remains in a draft state on the destination platform, it mitigates the risk of indirect prompt injection in processed content, as a human must manually review and publish the final result.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 25, 2026, 03:23 AM
Security Audit — agent-trust-hub — social-publishing-weapon