audience-research
Pass
Audited by Gen Agent Trust Hub on Aug 27, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted content from various social media platforms, creating a vulnerability surface where embedded instructions could influence agent behavior.
- Ingestion points: External content enters the agent's context through
sandbase_call_toolresults from platforms including Reddit, Twitter, Instagram, and Xiaohongshu as defined in SKILL.md and references/sandbase-api-map.md. - Boundary markers: The skill instructions do not provide explicit delimiters or instructions to treat external data as untrusted text, which is a standard safety practice for research agents.
- Capability inventory: The agent uses vendor tools
sandbase_describe_toolandsandbase_call_toolfor data retrieval; no sensitive file access or arbitrary command execution capabilities were identified. - Sanitization: The skill does not define any logic for filtering, sanitizing, or validating the content retrieved from social media gateways before synthesis.
Audit Metadata