social-scraping

Pass

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process large volumes of untrusted data from over 20 social media platforms, including TikTok, Instagram, and Reddit. This data includes user-generated comments, post descriptions, and video transcripts which can contain malicious instructions intended to influence the agent's behavior.
  • Ingestion points: External data enters the agent context via the stablesocial.dev API, specifically through endpoints like /api/sc/tiktok/post-comments and /api/sc/youtube/video/transcript (documented in SKILL.md).
  • Boundary markers: The instructions do not define boundary markers or provide guidelines for the agent to distinguish between its primary instructions and the content retrieved from social media.
  • Capability inventory: The skill uses the agentcash CLI tool to execute shell commands (npx agentcash@latest fetch) for data retrieval.
  • Sanitization: There is no evidence of content sanitization, filtering, or validation of the scraped social media data before it is presented to the agent.
  • [EXTERNAL_DOWNLOADS]: The documentation in rules/getting-started.md instructs the user to install an external dependency globally (npm install -g agentcash). This tool is required for the skill to function, as it handles authentication and payment for the scraping services.
  • [COMMAND_EXECUTION]: The skill documentation frequently utilizes shell commands via npx agentcash@latest fetch to trigger data collection jobs and poll for results. This pattern involves executing an external CLI tool with various arguments to interact with the stablesocial.dev infrastructure.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 21, 2026, 02:54 AM
Security Audit — agent-trust-hub — social-scraping