content
Pass
Audited by Gen Agent Trust Hub on Aug 18, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [SAFE]: The skill incorporates explicit safety instructions, requiring the agent to 'stop and get the user's explicit approval before any posting or engagement action'. It also recommends labeling all drafts as 'unposted', ensuring no automated changes are made to external platforms without oversight.\n- [COMMAND_EXECUTION]: The skill uses local Python scripts,
scripts/content-lint.pyandscripts/trends.py, to validate content specifications and generate trend reports. These scripts process local JSON data and do not perform network requests or execute arbitrary code.\n- [PROMPT_INJECTION]: The skill is designed to ingest and analyze external data from social media platforms (X, Instagram, TikTok), which presents a surface for indirect prompt injection.\n - Ingestion points: The agent scans live feeds and Trending panels through browser integration as specified in
references/viral-research.md.\n - Boundary markers: Instructions in
SKILL.mdandreferences/viral-research.mddirect the agent to focus on 'transferable patterns' and to 'strip the subject', which serves to isolate the structural data from potential malicious instructions in the source text.\n - Capability inventory: The agent's capabilities are limited to reading local files, writing drafts, and executing the provided validation scripts. It lacks the ability to autonomously post or perform unauthorized network actions.\n
- Sanitization: The provided scripts use standard JSON parsing and validate data against hardcoded platform limits, reducing the risk of processing malformed or malicious inputs.
Audit Metadata