link-in-bio-and-traffic

Pass

Audited by Gen Agent Trust Hub on Jul 16, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is entirely composed of documentation and instructional markdown files. It does not include any executable scripts, binaries, or automated command sequences.
  • [PROMPT_INJECTION]: The instructions do not contain bypass attempts, role-play injections, or commands to ignore safety guidelines. The skill presents an indirect prompt injection surface as it processes external brand and KPI data:
  • Ingestion points: Reads brand-profile and goals-and-kpis files for context.
  • Boundary markers: No explicit delimiters are defined for these input sources.
  • Capability inventory: Instructs the agent to use the WoopSocial tool for publishing posts.
  • Sanitization: No sanitization or validation of the input data is described.
  • [CREDENTIALS_UNSAFE]: No hardcoded API keys, tokens, or sensitive file paths were found. The skill advises the use of external third-party tools for landing pages and analytics without requesting credentials.
  • [DATA_EXFILTRATION]: No network exfiltration or unauthorized data access patterns were identified. The skill correctly identifies that analytics data must be retrieved from established external platforms like GA4.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 16, 2026, 06:01 PM
Security Audit — agent-trust-hub — link-in-bio-and-traffic