recoup-internal-social-ship-posts

Pass

Audited by Gen Agent Trust Hub on Jul 31, 2026

Risk Level: SAFE
Full Analysis
  • [DATA_EXFILTRATION]: The skill performs network requests to api.recoupable.dev. These communications are directed to the vendor's official infrastructure for intended functionality, such as scraping social media metrics and managing media uploads. No data is sent to unauthorized third-party domains.
  • [PROMPT_INJECTION]: The skill ingests untrusted data from external social media platforms via its scraping tool. This data is then used to inform the drafting of new posts. This constitutes a surface for indirect prompt injection, where content within a scraped post might attempt to influence the agent's drafting behavior.
  • Ingestion points: Social media post content fetched via api.recoupable.dev/api/artist/socials/scrape (Step 1).
  • Boundary markers: None explicitly defined in the instructions to separate scraped content from generation prompts.
  • Capability inventory: The skill has capabilities to perform network requests (curl) and publish content to LinkedIn and X via connector actions (Step 4).
  • Sanitization: No explicit sanitization or filtering of the scraped social media content is mentioned before it is processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 31, 2026, 02:49 PM
Security Audit — agent-trust-hub — recoup-internal-social-ship-posts