social-orchestrator

Pass

Audited by Gen Agent Trust Hub on Aug 3, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill facilitates the processing and cross-channel distribution of user-supplied content, media, and campaign objectives, which presents a surface for indirect prompt injection where malicious instructions embedded in the data could potentially influence the agent's behavior during publishing operations.\n
  • Ingestion points: Untrusted data enters the agent context through the content, media, and objective parameters of the /Publish_All, /Campaign, and /Content_Plan workflows in SKILL.md.\n
  • Boundary markers: The skill lacks explicit delimiters or specific instructions to treat incoming user content strictly as data, which may lead the agent to interpret embedded commands as legitimate directives.\n
  • Capability inventory: The skill has access to powerful automated communication tools, including the instagram, telegram, and whatsapp-cloud-api skills, which can perform network-based API actions and public content distribution.\n
  • Sanitization: No sanitization or filtering logic is present to validate or escape user input before it is passed to the underlying platform tools.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 3, 2026, 05:31 PM
Security Audit — agent-trust-hub — social-orchestrator