social-intel

Pass

Audited by Gen Agent Trust Hub on Jul 29, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [PROMPT_INJECTION]: Indirect prompt injection surface identified through the ingestion of external web content. \n
  • Ingestion points: Search result snippets retrieved from Exa and Tavily as defined in manifest.json. \n
  • Boundary markers: Absent; instructions do not explicitly mandate the use of XML delimiters or 'ignore' instructions for external snippets. \n
  • Capability inventory: Limited to network API calls via vendor-provided CLI tools; no arbitrary local code execution or file system access. \n
  • Sanitization: No specific filtering or escaping of retrieved search text is described in the workflow. \n- [COMMAND_EXECUTION]: The skill documentation utilizes the 'selat' and 'selat-pay' CLI utilities for installation, validation, and execution. These are standard vendor resources for the SELAT-AI platform. \n- [EXTERNAL_DOWNLOADS]: Network operations target api.exa.ai and x402.tavily.com. These are legitimate search service endpoints required for the skill's stated purpose of gathering intelligence and providing corroborated briefs.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 29, 2026, 07:34 PM
Security Audit — agent-trust-hub — social-intel