kelly-social
Pass
Audited by Gen Agent Trust Hub on Aug 25, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted external content from social media platforms (X, Facebook, Instagram) which creates a surface for indirect prompt injection attacks.\n
- Ingestion points: Ingests social media mentions and comments through
scripts/ingest_snapshot.mjspopulated via browser automation or analytics exports.\n - Boundary markers: The skill uses a
social-qaquality gate insocial-model.jsto evaluate outgoing content, andSKILL.mddefines boundaries for data collection.\n - Capability inventory: The agent can draft posts, replies, and scripts, and perform browser automation for data collection.\n
- Sanitization: The skill normalizes metrics and validates outgoing drafts, but it does not explicitly sanitize incoming social media text against injection patterns before the agent processes it for drafting replies.
Audit Metadata