account-warming-automation

Pass

Audited by Gen Agent Trust Hub on Mar 18, 2026

Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADSDATA_EXFILTRATION
Full Analysis
  • [PROMPT_INJECTION]: The skill provides instructions for the agent to mimic human behavior to specifically bypass the security filters and bot-detection systems of third-party social media platforms (Instagram, TikTok, Twitter, LinkedIn, Facebook, Reddit).\n- [PROMPT_INJECTION]: Indirect prompt injection surface identified through untrusted data processing.\n
  • Ingestion points: Social media platform feeds and profile content processed during browsing sessions (SKILL.md).\n
  • Boundary markers: Absent.\n
  • Capability inventory: Browser automation, proxy control, and engagement actions (SKILL.md).\n
  • Sanitization: Absent.\n- [EXTERNAL_DOWNLOADS]: The skill references an external residential proxy provider (BirdProxies) and includes configuration instructions for routing traffic through their infrastructure.\n- [DATA_EXFILTRATION]: Configures the agent to route all browsing traffic through a third-party proxy provider, which introduces a point for potential monitoring or interception of the agent's web activity.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 18, 2026, 09:22 AM
Security Audit — agent-trust-hub — account-warming-automation