social-proof-research

Pass

Audited by Gen Agent Trust Hub on Aug 27, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to research and collect data from external social media platforms (Twitter, Reddit, Google Maps, Xiaohongshu, LinkedIn). This ingestion of untrusted external content creates an attack surface for indirect prompt injection.\n
  • Ingestion points: Data is ingested from external platforms via the sandbase_call_tool mentioned in SKILL.md and references/sandbase-api-map.md.\n
  • Boundary markers: The skill does not define specific delimiters or instructions to ignore embedded instructions in the retrieved data.\n
  • Capability inventory: The skill utilizes sandbase_call_tool for network API access as defined in SKILL.md.\n
  • Sanitization: No sanitization or filtering logic is specified for the external content.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 27, 2026, 11:31 PM
Security Audit — agent-trust-hub — social-proof-research