influencer-analytics
Pass
Audited by Gen Agent Trust Hub on Aug 27, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests and processes data from external social media platforms (TikTok, Instagram, YouTube, Bilibili, and Kuaishou), creating a surface for potential indirect prompt injection attacks.
- Ingestion points: External influencer metrics and profile data retrieved via
sandbase_call_toolas referenced in SKILL.md. - Boundary markers: The instructions do not define specific delimiters or instructions to ignore embedded commands within the fetched data.
- Capability inventory: The skill is limited to read-only data retrieval using
sandbase_describe_toolandsandbase_call_tool. - Sanitization: The instructions do not specify any validation or sanitization of the external content before processing.
Audit Metadata