influencer-discovery-brief

Pass

Audited by Gen Agent Trust Hub on Sep 13, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze data from external, untrusted sources including creator profiles, social media comments, community threads, and third-party exports (Workflow Steps 5 and 6 in SKILL.md).
  • Ingestion points: Untrusted data enters the agent context through manual profile reviews, social listening queries, and the processing of community mentions or support threads.
  • Boundary markers: The instructions do not define clear delimiters or specific "ignore embedded instructions" directives for the external content being analyzed.
  • Capability inventory: The skill's capabilities are restricted to reasoning, scoring, and generating a discovery brief. It does not perform high-risk operations such as arbitrary code execution, filesystem writes, or unauthorized network activity.
  • Sanitization: There are no explicit requirements for sanitizing or filtering external text to mitigate potential prompt injection attacks hidden within social media data.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 13, 2026, 09:17 PM
Security Audit — agent-trust-hub — influencer-discovery-brief