pr-media-monitor

Pass

Audited by Gen Agent Trust Hub on Aug 27, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONNO_CODE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill's primary function is to ingest and synthesize data from external sources, including Google News, Twitter, LinkedIn, and general web searches. This creates an attack surface where malicious instructions could be embedded in the content being monitored.
  • Ingestion points: External data enters the agent context via google_news_bulk_articles, tavily_search, twitter_web_search_timeline, linkedin_web_v2_user_posts, and linkedin_web_v2_company_posts tools as described in SKILL.md and references/sandbase-api-map.md.
  • Boundary markers: The instructions do not define specific delimiters or guardrail prompts to instruct the agent to ignore instructions contained within the retrieved media content.
  • Capability inventory: The skill utilizes the sandbase_call_tool and sandbase_describe_tool functions to fetch external data.
  • Sanitization: There are no explicit instructions for the agent to sanitize, escape, or validate the content retrieved from external search results.
  • [NO_CODE]: The skill consists entirely of instructional markdown and configuration metadata. It does not include any accompanying scripts, executables, or binary files, which significantly reduces the risk of direct malicious code execution.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 27, 2026, 11:31 PM
Security Audit — agent-trust-hub — pr-media-monitor