hashtag-tracker

Pass

Audited by Gen Agent Trust Hub on Aug 27, 2026

Risk Level: SAFENO_CODE
Full Analysis
  • [SAFE]: The skill utilizes vendor-provided research tools (sandbase_describe_tool, sandbase_call_tool) to retrieve data from social media platforms. These resources are legitimate for the skill's stated purpose.
  • [NO_CODE]: The skill is comprised of markdown instructions and reference maps only; it does not include scripts, executables, or automated dependency installations.
  • [SAFE]: Instructions explicitly constrain the agent to read-only research, citation of sources, and separation of factual observations from interpretation, mitigating unauthorized actions.
  • [INDIRECT_PROMPT_INJECTION]: The skill possesses a surface for indirect prompt injection via external social media content, but the risk is negligible due to restricted capabilities.
  • Ingestion points: Data from Instagram, TikTok, Twitter, Xiaohongshu, and Douyin is ingested through tool calls in SKILL.md and references/sandbase-api-map.md.
  • Boundary markers: Absent; the skill does not define specific prompt delimiters, although it provides guidelines for factual synthesis.
  • Capability inventory: None; the skill does not have access to file system writes, shell execution, or privileged network operations.
  • Sanitization: Absent; the instructions do not specify sanitization for the ingested social media data.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 27, 2026, 11:31 PM
Security Audit — agent-trust-hub — hashtag-tracker