content-performance
Pass
Audited by Gen Agent Trust Hub on Sep 26, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from social media platforms, which may contain malicious instructions.
- Ingestion points: Data is ingested through tools like
youtube_web_v2_video_comments,instagram_v3_post_comments, andtwitter_web_tweet_detailas defined inSKILL.mdandreferences/sandbase-api-map.md. - Boundary markers: There are no explicit instructions to use delimiters or ignore instructions embedded within the fetched content to prevent the agent from accidentally executing commands found in comments or tweets.
- Capability inventory: The skill utilizes a suite of
sandbasetools (e.g.,sandbase_call_tool) to perform research and synthesize data. - Sanitization: The instructions lack guidance for the agent to sanitize, filter, or validate the content retrieved from external social media APIs before processing it.
Audit Metadata