link-in-bio-and-traffic
Pass
Audited by Gen Agent Trust Hub on Jul 16, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill is entirely composed of documentation and instructional markdown files. It does not include any executable scripts, binaries, or automated command sequences.
- [PROMPT_INJECTION]: The instructions do not contain bypass attempts, role-play injections, or commands to ignore safety guidelines. The skill presents an indirect prompt injection surface as it processes external brand and KPI data:
- Ingestion points: Reads brand-profile and goals-and-kpis files for context.
- Boundary markers: No explicit delimiters are defined for these input sources.
- Capability inventory: Instructs the agent to use the WoopSocial tool for publishing posts.
- Sanitization: No sanitization or validation of the input data is described.
- [CREDENTIALS_UNSAFE]: No hardcoded API keys, tokens, or sensitive file paths were found. The skill advises the use of external third-party tools for landing pages and analytics without requesting credentials.
- [DATA_EXFILTRATION]: No network exfiltration or unauthorized data access patterns were identified. The skill correctly identifies that analytics data must be retrieved from established external platforms like GA4.
Audit Metadata