social-campaign

Pass

Audited by Gen Agent Trust Hub on Jul 14, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: Executes the typefully.js and mktg CLI tools to manage social media draft queues, publish content, and perform brand health checks.
  • [EXTERNAL_DOWNLOADS]: Communicates with Typefully and Postiz, which are established and well-known social media management services, to facilitate content distribution.
  • [PROMPT_INJECTION]: Exhibits an indirect prompt injection surface due to the requirement to read and analyze previous social media posts for voice calibration.
  • Ingestion points: Retrieves published posts from Typefully and reads brand identity files from the local filesystem.
  • Boundary markers: Does not implement specific delimiters or warnings to ignore instructions that might be embedded in the ingested historical content.
  • Capability inventory: Possesses the capability to execute shell commands (Bash) and write files to campaign directories.
  • Sanitization: Ingested text is processed directly for style analysis without explicit sanitization or filtering of potential embedded instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 14, 2026, 02:06 PM
Security Audit — agent-trust-hub — social-campaign