content-performance

Pass

Audited by Gen Agent Trust Hub on Sep 26, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from social media platforms, which may contain malicious instructions.
  • Ingestion points: Data is ingested through tools like youtube_web_v2_video_comments, instagram_v3_post_comments, and twitter_web_tweet_detail as defined in SKILL.md and references/sandbase-api-map.md.
  • Boundary markers: There are no explicit instructions to use delimiters or ignore instructions embedded within the fetched content to prevent the agent from accidentally executing commands found in comments or tweets.
  • Capability inventory: The skill utilizes a suite of sandbase tools (e.g., sandbase_call_tool) to perform research and synthesize data.
  • Sanitization: The instructions lack guidance for the agent to sanitize, filter, or validate the content retrieved from external social media APIs before processing it.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 26, 2026, 07:27 AM
Security Audit — agent-trust-hub — content-performance