social-captions

Pass

Audited by Gen Agent Trust Hub on Aug 17, 2026

Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to process untrusted user material, including competitor posts, scripts, and web links. Because it is configured with access to tools such as Bash and Write, and lacks explicit boundary markers or sanitization logic for ingested data, it presents a potential surface for indirect prompt injection.\n
  • Ingestion points: External material (text, images, links, competitor posts) processed in the main workflow defined in SKILL.md.\n
  • Boundary markers: None. The skill does not provide instructions to separate user-provided data from agent instructions.\n
  • Capability inventory: The environment permits the use of Bash, Read, Write, Edit, Glob, and Grep.\n
  • Sanitization: None. The skill does not specify any filtering or validation for external content.\n- [EXTERNAL_DOWNLOADS]: The installation process involves cloning a repository from the author's GitHub account (github.com/rediumvex/social-media-caption-generator-claude.git). This represents standard installation behavior for vendor-provided resources.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 17, 2026, 04:48 AM
Security Audit — agent-trust-hub — social-captions