social-scraping
Pass
Audited by Gen Agent Trust Hub on Sep 21, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process large volumes of untrusted data from over 20 social media platforms, including TikTok, Instagram, and Reddit. This data includes user-generated comments, post descriptions, and video transcripts which can contain malicious instructions intended to influence the agent's behavior.
- Ingestion points: External data enters the agent context via the
stablesocial.devAPI, specifically through endpoints like/api/sc/tiktok/post-commentsand/api/sc/youtube/video/transcript(documented inSKILL.md). - Boundary markers: The instructions do not define boundary markers or provide guidelines for the agent to distinguish between its primary instructions and the content retrieved from social media.
- Capability inventory: The skill uses the
agentcashCLI tool to execute shell commands (npx agentcash@latest fetch) for data retrieval. - Sanitization: There is no evidence of content sanitization, filtering, or validation of the scraped social media data before it is presented to the agent.
- [EXTERNAL_DOWNLOADS]: The documentation in
rules/getting-started.mdinstructs the user to install an external dependency globally (npm install -g agentcash). This tool is required for the skill to function, as it handles authentication and payment for the scraping services. - [COMMAND_EXECUTION]: The skill documentation frequently utilizes shell commands via
npx agentcash@latest fetchto trigger data collection jobs and poll for results. This pattern involves executing an external CLI tool with various arguments to interact with thestablesocial.devinfrastructure.
Audit Metadata