influencer-outreach

Pass

Audited by Gen Agent Trust Hub on Sep 13, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to browse the web and load external creator posts or profiles to ground personalization, which creates a potential vector for indirect prompt injection if an attacker embeds malicious instructions in their public content.\n
  • Ingestion points: External web content from influencer profiles and social media posts (Workflow Step 2 in SKILL.md).\n
  • Boundary markers: There are no explicit delimiters instructed for the web content, but the workflow requires verifying fit evidence against specific posts.\n
  • Capability inventory: The skill only performs text generation and artifact creation. It does not have permissions for sensitive file access, network exfiltration, or code execution.\n
  • Sanitization: The workflow includes mandatory human-in-the-loop review (Workflow Step 10) and a humanization requirement (Workflow Step 8), which ensure that any malicious influence from external data is caught by the user before the outreach is sent.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 13, 2026, 09:17 PM
Security Audit — agent-trust-hub — influencer-outreach