market-social

Pass

Audited by Gen Agent Trust Hub on Apr 18, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: Indirect Prompt Injection surface via external URL ingestion. The skill retrieves brand context from user-provided URLs in Phase 1 without sanitization or boundary markers. This allows untrusted data to enter the agent's context, where it could potentially manipulate the content written to SOCIAL-CALENDAR.md. • Ingestion points: Website fetching logic described in Phase 1 (SKILL.md) to understand brand and audience. • Boundary markers: Absent. There are no instructions to the agent to treat external website content as untrusted or to ignore directives found within the fetched data. • Capability inventory: The skill instructions involve file writing (SOCIAL-CALENDAR.md) and summarizing content for the user. • Sanitization: Absent. No validation or filtering logic is specified for the data retrieved from external sources.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 18, 2026, 12:08 PM
Security Audit — agent-trust-hub — market-social