soku-cli-integration

Pass

Audited by Gen Agent Trust Hub on Jul 30, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill facilitates the installation of the @soku-ai/cli package from the NPM registry. This is a standard installation process for the vendor's command-line tool.
  • [COMMAND_EXECUTION]: The skill provides a wide range of CLI commands for interacting with advertising and analytics platforms. Commands like soku ads, soku ga4, and soku posthog allow agents to retrieve data and manage marketing assets through structured JSON outputs.
  • [PROMPT_INJECTION]: The skill processes external data from advertising and analytics platforms, which represents an indirect prompt injection surface. However, the risk is mitigated by a human-in-the-loop requirement for sensitive actions.
  • Ingestion points: Data retrieved via reporting and analytics commands (e.g., soku ads query-single-dimension).
  • Boundary markers: None explicitly mentioned in the provided examples to separate third-party data from agent instructions.
  • Capability inventory: Includes capabilities to publish SEO content, create ad campaigns, and upload files to a context hub.
  • Sanitization: Relies on the soku review workflow, requiring human approval for all delivery-changing operations to prevent malicious execution.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 30, 2026, 12:39 AM
Security Audit — agent-trust-hub — soku-cli-integration