commerce-influencer-collab

Pass

Audited by Gen Agent Trust Hub on Aug 19, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: The skill does not contain instructions attempting to override agent behavior, bypass safety guidelines, or extract system prompts. The instructional language is strictly relevant to its marketing purpose.
  • [DATA_EXPOSURE_AND_EXFILTRATION]: No hardcoded credentials, sensitive file paths, or unauthorized network operations were detected.
  • [OBFUSCATION]: The content is clear and uses no Base64, zero-width characters, or other encoding techniques to hide information.
  • [UNVERIFIABLE_DEPENDENCIES_AND_REMOTE_CODE_EXECUTION]: The skill does not perform any external package installations or execute remote scripts. References to other tools (e.g., ai-slop-reviewer) are consistent with the vendor's ecosystem.
  • [PRIVILEGE_ESCALATION]: No commands for escalating privileges or modifying system-level settings were found.
  • [PERSISTENCE_MECHANISMS]: The skill does not attempt to create persistent access via shell profiles, cron jobs, or registry keys.
  • [METADATA_POISONING]: Metadata fields (name, description, version) accurately reflect the skill's functionality and do not contain deceptive instructions.
  • [INDIRECT_PROMPT_INJECTION]: While the skill processes user-provided brand and budget data, it does not interpolate this data into executable commands or unsafe contexts. It provides static checklists and guidelines.
  • [TIME_DELAYED_OR_CONDITIONAL_ATTACKS]: No logic was found that gates dangerous operations behind time or environment checks.
  • [DYNAMIC_EXECUTION]: The skill does not generate or execute code at runtime.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 19, 2026, 01:41 PM
Security Audit — agent-trust-hub — commerce-influencer-collab