facebook-reply

Pass

Audited by Gen Agent Trust Hub on Jul 13, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection (Category 8) because it incorporates untrusted external data (Facebook comments) into the model's processing context.
  • Ingestion points: The workflow in SKILL.md instructs the agent to treat everything following the fbr trigger as the context for the reply.
  • Boundary markers: The instructions do not define boundary markers (such as triple backticks or XML tags) to distinguish between user-provided comment text and the skill's instructions.
  • Capability inventory: The skill is restricted to text generation. It does not utilize any tools for network access, file system modification, or command execution, which limits the potential impact of an injection to the generated output.
  • Sanitization: No sanitization, escaping, or validation logic is present to filter malicious instructions embedded within the processed comments.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 13, 2026, 01:07 AM
Security Audit — agent-trust-hub — facebook-reply