social-proof-research
Pass
Audited by Gen Agent Trust Hub on Aug 27, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to research and collect data from external social media platforms (Twitter, Reddit, Google Maps, Xiaohongshu, LinkedIn). This ingestion of untrusted external content creates an attack surface for indirect prompt injection.\n
- Ingestion points: Data is ingested from external platforms via the
sandbase_call_toolmentioned inSKILL.mdandreferences/sandbase-api-map.md.\n - Boundary markers: The skill does not define specific delimiters or instructions to ignore embedded instructions in the retrieved data.\n
- Capability inventory: The skill utilizes
sandbase_call_toolfor network API access as defined inSKILL.md.\n - Sanitization: No sanitization or filtering logic is specified for the external content.
Audit Metadata