douyin-research

Pass

Audited by Gen Agent Trust Hub on Aug 27, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external data from Douyin (video titles, descriptions, and user profiles) which could contain malicious instructions designed to influence the agent's behavior.
  • Ingestion points: Data enters the context via search results from tools like douyin_search_general_search_v2, douyin_search_video_search_v2, and douyin_search_user_search_v2 (SKILL.md, references/sandbase-api-map.md).
  • Boundary markers: The instructions do not specify the use of delimiters or specific warnings to ignore instructions embedded in the search results.
  • Capability inventory: The agent uses sandbase_call_tool to interact with the SandBase gateway (SKILL.md).
  • Sanitization: There is no evidence of sanitization or filtering of the content retrieved from external sources before it is processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 27, 2026, 11:30 PM
Security Audit — agent-trust-hub — douyin-research