skills/sergekostenchuk/ui-ux-agent-skill-system/external-authority-placement-scout/Gen Agent Trust Hub
external-authority-placement-scout
Pass
Audited by Gen Agent Trust Hub on Jul 29, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill processes untrusted data from external sources to identify SEO opportunities, which presents a surface for indirect prompt injection.
- Ingestion points: External content gathered from "user-provided platforms" and "approved public research" as defined in the
Workflowsection ofSKILL.mdandreferences/scouting-workflow.md. - Boundary markers: Absent. The instructions do not specify using delimiters or explicit warnings to ignore embedded commands when processing external text.
- Capability inventory: The agent is restricted to local file reading, draft generation, and local subprocess execution for validation scripts (
lint_production_skill.py,lint_skill_cluster.py). Automated external actions like posting, account edits, or outreach are explicitly forbidden. - Sanitization: Absent. The workflow does not include steps to sanitize or filter potential malicious instructions from the analyzed external content.
Audit Metadata