influencer-outreach
Pass
Audited by Gen Agent Trust Hub on Sep 13, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to browse the web and load external creator posts or profiles to ground personalization, which creates a potential vector for indirect prompt injection if an attacker embeds malicious instructions in their public content.\n
- Ingestion points: External web content from influencer profiles and social media posts (Workflow Step 2 in
SKILL.md).\n - Boundary markers: There are no explicit delimiters instructed for the web content, but the workflow requires verifying fit evidence against specific posts.\n
- Capability inventory: The skill only performs text generation and artifact creation. It does not have permissions for sensitive file access, network exfiltration, or code execution.\n
- Sanitization: The workflow includes mandatory human-in-the-loop review (Workflow Step 10) and a humanization requirement (Workflow Step 8), which ensure that any malicious influence from external data is caught by the user before the outreach is sent.
Audit Metadata