social-listening
Pass
Audited by Gen Agent Trust Hub on Sep 29, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection as it aggregates and processes content from external, untrusted social media platforms (Twitter, Reddit, Threads, Weibo, Bilibili).
- Ingestion points: Data is ingested through tools like
twitter_web_search_timeline,reddit_app_dynamic_search,threads_web_search_recent,weibo_web_search, andbilibili_web_general_searchdefined inSKILL.md. - Boundary markers: There are no explicit delimiters or instructions provided to the agent to ignore or isolate potentially malicious instructions embedded in the social media content.
- Capability inventory: The skill is primarily focused on research and synthesis; the guidelines in
SKILL.mdandreferences/sandbase-api-map.mdexplicitly restrict the agent to read-only research and forbid taking actions on external platforms. - Sanitization: No specific sanitization, filtering, or validation logic is defined for the external data before it is processed by the agent.
Audit Metadata