tt-trend-mapper

Pass

Audited by Gen Agent Trust Hub on Sep 11, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes user-provided TikTok URLs and trend descriptions which are ingested directly into the agent context, creating a surface for potential indirect prompt injection.
  • Ingestion points: Untrusted trend descriptions and video URLs are ingested as described in the Steps section of SKILL.md.
  • Boundary markers: The instructions do not define specific delimiters or instructions to ignore embedded commands within the user-provided trend data.
  • Capability inventory: The skill generates scripts and interacts with other internal skills (tt-humanizer, tt-caption-writer); it does not have access to sensitive file systems or unauthorized network operations.
  • Sanitization: No explicit sanitization or validation of the external input is performed before the data is used to generate script content.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 11, 2026, 01:37 PM
Security Audit — agent-trust-hub — tt-trend-mapper