brand-monitoring
Pass
Audited by Gen Agent Trust Hub on Aug 27, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process untrusted data from external sources including Twitter, Reddit, Weibo, Xiaohongshu, and general news platforms.
- Ingestion points: External data enters the agent context via search tools such as
twitter_web_search_timeline,reddit_app_dynamic_search,tavily_search,google_news_bulk_articles,xiaohongshu_app_v2_search_notes, andweibo_web_searchas defined inreferences/sandbase-api-map.md. - Boundary markers: The instructions do not specify the use of delimiters or specific instructions to the agent to ignore potentially malicious embedded content within the search results.
- Capability inventory: The skill is primarily focused on data aggregation, sentiment analysis, and synthesis of mentions. It does not appear to possess capabilities for file writing or arbitrary command execution that would be highly exploitable by injected content.
- Sanitization: There are no explicit instructions for sanitizing or filtering the content retrieved from external platforms before it is analyzed by the agent.
Audit Metadata