reddit-customer-insights

Pass

Audited by Gen Agent Trust Hub on Aug 27, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted third-party content from Reddit posts and comments, which could contain instructions designed to bypass agent constraints or influence behavior. * Ingestion points: External data is brought into the agent context via the reddit_app_dynamic_search, reddit_app_topic_feed, and reddit_app_post_details tools as defined in the SKILL.md workflow and the references/sandbase-api-map.md capability list. * Boundary markers: There are no explicit instructions to use delimiters or ignore embedded directives within the ingested Reddit content, though the synthesis workflow (Step 6) encourages structured reporting. * Capability inventory: The skill possesses the ability to call various Reddit tools through the sandbase_call_tool gateway. * Sanitization: The instructions do not require the agent to sanitize or filter the raw text retrieved from external threads before analysis.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 27, 2026, 11:31 PM
Security Audit — agent-trust-hub — reddit-customer-insights