social-distribute
Pass
Audited by Gen Agent Trust Hub on May 20, 2026
Risk Level: SAFECOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses node and skflow to execute shell commands for environment detection and automation control.
- [REMOTE_CODE_EXECUTION]: The skill executes an opaque, pre-compiled JavaScript file (.skflow/skills/social-distribute/script.compiled.js), which limits transparency regarding its browser-level operations.
- [PROMPT_INJECTION]: Untrusted data from the topic field in the SOCIAL_DISTRIBUTE_INPUT environment variable is interpolated into LLM prompts for copywriting. The skill lacks documented sanitization or boundary markers for this input, and possesses capabilities like browser automation (via CDP) and shell execution.
Audit Metadata