skills/melumuccu/ai/social/Gen Agent Trust Hub

social

Pass

Audited by Gen Agent Trust Hub on Aug 26, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill ingests untrusted data from various social media platforms to perform automated triage, scoring, and drafting, creating a surface for indirect prompt injection.\n
  • Ingestion points: Retrieves data from Reddit, Hacker News, Bluesky, LinkedIn, and X via public APIs and browser sessions (references/listening.md).\n
  • Boundary markers: Absent; no specific instructions to treat ingested text as untrusted or to use delimiters.\n
  • Capability inventory: Agent uses retrieved data to score posts and draft replies, utilizing curl and jq for retrieval.\n
  • Sanitization: Not present.\n- [COMMAND_EXECUTION]: The skill provides shell command templates (curl, jq, xmllint) for the agent to fetch and process data from external social media endpoints (references/listening.md).\n- [EXTERNAL_DOWNLOADS]: Fetches data from well-known services including Reddit, Hacker News (Algolia API), and Bluesky for monitoring purposes.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 26, 2026, 04:18 AM
Security Audit — agent-trust-hub — social