facebook-strategy

Pass

Audited by Gen Agent Trust Hub on Jul 16, 2026

Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
  • [PROMPT_INJECTION]: The skill instructs the agent to draft replies to user comments on social media, creating an indirect prompt injection surface. Malicious content within a comment could potentially override the agent's instructions or influence its generated responses.\n
  • Ingestion points: Processes external user comments to generate reply copy (SKILL.md).\n
  • Boundary markers: Lacks instructions for using delimiters or explicit warnings to ignore embedded commands within user content.\n
  • Capability inventory: Capable of drafting social media posts, Reels scripts, and replies, and interacts with the WoopSocial scheduling tool (SKILL.md).\n
  • Sanitization: No sanitization or filtering logic is defined for the external text being processed.\n- [NO_CODE]: The skill consists entirely of Markdown documentation and JSON configuration files. No executable scripts (e.g., Python, JavaScript, Shell) are included in the skill package.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 16, 2026, 06:02 PM
Security Audit — agent-trust-hub — facebook-strategy