social-cli
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill enables an agent to process untrusted social media data (mentions, replies, feed content) retrieved via the
synccommand and stored ininbox-*.yamlfiles. Malicious content within these notifications could potentially influence an agent's subsequent decisions if it is programmed to respond to them. The skill includes inherent mitigations such as character limit enforcement (300 for Bluesky, 280 for X) and strict YAML schema validation for all outgoing actions. - [EXTERNAL_DOWNLOADS]: The skill's setup instructions involve downloading the source code from the official GitHub repository for 'letta-ai'. This is a standard installation process for the tool.
- [COMMAND_EXECUTION]: The provided documentation describes executing shell commands for installation (
git clone,pnpm install) and operational automation (bash scripts and crontab patterns). These are intended for the initial setup and routine execution of the social media agent loop.
Audit Metadata