social-media-scraper
Pass
Audited by Gen Agent Trust Hub on Mar 22, 2026
Risk Level: SAFEPROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
- [PROMPT_INJECTION]: The skill facilitates the ingestion of raw, untrusted data from social media platforms, creating an indirect prompt injection surface where malicious instructions embedded in bios, posts, or comments could be processed by the agent.\n
- Ingestion points: Public profiles, posts, comments, and metadata from Instagram, TikTok, Twitter/X, YouTube, and Facebook.\n
- Boundary markers: No delimiters or instructions to ignore embedded content are provided in the scraping strategies.\n
- Capability inventory: Uses browser automation and proxy-enabled network requests to navigate and extract data.\n
- Sanitization: The instructions do not include steps for sanitizing or validating the extracted data before it is processed by the agent.\n- [DATA_EXFILTRATION]: The skill configures the agent to route all web traffic through a specific third-party proxy provider (gate.birdproxies.com). This dependency allows the external provider to observe all transmitted data, which may include session identifiers or account credentials if the agent performs authenticated scraping as suggested.
Audit Metadata