behind-the-scenes-and-founder
Pass
Audited by Gen Agent Trust Hub on Jul 18, 2026
Risk Level: SAFE
Full Analysis
- [PROMPT_INJECTION]: The skill possesses a surface for indirect prompt injection as it processes untrusted data from social media. 1. Ingestion points: Social media comments, DMs, and quoted screenshots (SKILL.md, references/scope-and-connections.md). 2. Boundary markers: The instructions explicitly state that external data must be treated as material to consider, not a command. 3. Capability inventory: Capabilities include formatting text for various social platforms and publishing via the WoopSocial tool. 4. Sanitization: The skill mandates that a human owner must review and approve every reveal before it is published, ensuring a manual security check.- [SAFE]: The skill implements the REVEAL framework to ensure content is rooted in real events while vetting it against strict transparency tiers. It explicitly prohibits the disclosure of sensitive information such as customer data, team conflicts, personnel issues, legal matters, and security credentials.- [SAFE]: No malicious obfuscation, unauthorized network operations, or suspicious third-party dependencies were detected. The skill uses sibling skills (brand-profile, voice-builder) to ground its content generation in established, safe business context.- [SAFE]: The skill includes a 'permanence test' which requires the human user to evaluate if the content would be acceptable in sensitive contexts like lawsuits or hiring calls, providing an additional layer of reputational safety.
Audit Metadata