douyin-research
Pass
Audited by Gen Agent Trust Hub on Aug 27, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes external data from Douyin (video titles, descriptions, and user profiles) which could contain malicious instructions designed to influence the agent's behavior.
- Ingestion points: Data enters the context via search results from tools like
douyin_search_general_search_v2,douyin_search_video_search_v2, anddouyin_search_user_search_v2(SKILL.md, references/sandbase-api-map.md). - Boundary markers: The instructions do not specify the use of delimiters or specific warnings to ignore instructions embedded in the search results.
- Capability inventory: The agent uses
sandbase_call_toolto interact with the SandBase gateway (SKILL.md). - Sanitization: There is no evidence of sanitization or filtering of the content retrieved from external sources before it is processed by the agent.
Audit Metadata