kol-discovery

Pass

Audited by Gen Agent Trust Hub on Aug 27, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted third-party content from social media profiles (TikTok, Instagram, YouTube, and Xiaohongshu) which could contain hidden instructions targeting the AI agent.
  • Ingestion points: Data is retrieved via tools such as tiktok_app_v3_creator_info, instagram_v3_user_profile, youtube_web_v2_channel_description, and xiaohongshu_app_v2_user_info as described in SKILL.md.
  • Boundary markers: The skill lacks explicit boundary markers or instructions for the agent to ignore potentially malicious content embedded in the retrieved social media metadata.
  • Capability inventory: The skill uses sandbase_call_tool to perform search and evaluation tasks based on input that may be derived from previously retrieved external data.
  • Sanitization: No evidence of sanitization, filtering, or escaping for external content is present in the instruction set.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 27, 2026, 11:30 PM
Security Audit — agent-trust-hub — kol-discovery