recoup-content-reactive-post

Pass

Audited by Gen Agent Trust Hub on Jul 23, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses curl, jq, and sed to automate API requests and process local artist metadata. These are standard operations for a workspace-integrated tool.
  • [PROMPT_INJECTION]: The skill uses instructions in SKILL.md and references/analyze-gate.md to establish a mandatory review process. This prevents the agent from reporting success prematurely, serving as a protective quality barrier rather than a malicious bypass.
  • [EXTERNAL_DOWNLOADS]: Integrated API calls to api.recoupable.dev are used to retrieve artist metrics, career milestones, and to perform video analysis. These are functional dependencies of the Recoup platform.
  • [SAFE]: The skill ingests external research data from research/web and research/deep (documented in references/research-context.md). While this represents a potential surface for indirect prompt injection from web-sourced text, the data is primarily used to inform creative direction and tone, and the agent is instructed to prioritize structured workspace data for factual content.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 23, 2026, 08:25 AM
Security Audit — agent-trust-hub — recoup-content-reactive-post