social-listening

Pass

Audited by Gen Agent Trust Hub on Sep 29, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection as it aggregates and processes content from external, untrusted social media platforms (Twitter, Reddit, Threads, Weibo, Bilibili).
  • Ingestion points: Data is ingested through tools like twitter_web_search_timeline, reddit_app_dynamic_search, threads_web_search_recent, weibo_web_search, and bilibili_web_general_search defined in SKILL.md.
  • Boundary markers: There are no explicit delimiters or instructions provided to the agent to ignore or isolate potentially malicious instructions embedded in the social media content.
  • Capability inventory: The skill is primarily focused on research and synthesis; the guidelines in SKILL.md and references/sandbase-api-map.md explicitly restrict the agent to read-only research and forbid taking actions on external platforms.
  • Sanitization: No specific sanitization, filtering, or validation logic is defined for the external data before it is processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 29, 2026, 04:42 AM
Security Audit — agent-trust-hub — social-listening