audience-research

Pass

Audited by Gen Agent Trust Hub on Aug 27, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted content from various social media platforms, creating a vulnerability surface where embedded instructions could influence agent behavior.
  • Ingestion points: External content enters the agent's context through sandbase_call_tool results from platforms including Reddit, Twitter, Instagram, and Xiaohongshu as defined in SKILL.md and references/sandbase-api-map.md.
  • Boundary markers: The skill instructions do not provide explicit delimiters or instructions to treat external data as untrusted text, which is a standard safety practice for research agents.
  • Capability inventory: The agent uses vendor tools sandbase_describe_tool and sandbase_call_tool for data retrieval; no sensitive file access or arbitrary command execution capabilities were identified.
  • Sanitization: The skill does not define any logic for filtering, sanitizing, or validating the content retrieved from social media gateways before synthesis.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 27, 2026, 11:31 PM
Security Audit — agent-trust-hub — audience-research