kol-discovery
Pass
Audited by Gen Agent Trust Hub on Aug 27, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted third-party content from social media profiles (TikTok, Instagram, YouTube, and Xiaohongshu) which could contain hidden instructions targeting the AI agent.
- Ingestion points: Data is retrieved via tools such as
tiktok_app_v3_creator_info,instagram_v3_user_profile,youtube_web_v2_channel_description, andxiaohongshu_app_v2_user_infoas described inSKILL.md. - Boundary markers: The skill lacks explicit boundary markers or instructions for the agent to ignore potentially malicious content embedded in the retrieved social media metadata.
- Capability inventory: The skill uses
sandbase_call_toolto perform search and evaluation tasks based on input that may be derived from previously retrieved external data. - Sanitization: No evidence of sanitization, filtering, or escaping for external content is present in the instruction set.
Audit Metadata