youtube-long-form
Pass
Audited by Gen Agent Trust Hub on Jul 16, 2026
Risk Level: SAFEDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
- [SAFE]: The skill's instructions and reference files contain no evidence of malicious code, obfuscation, or unauthorized access. All identified external resources are either vendor-owned or well-known services.
- [DATA_EXFILTRATION]: The skill references network endpoints at
api.woopsocial.comfor content scheduling. These endpoints are vendor-owned resources for the author 'social-media-skills' and are used for their declared purpose. - [PROMPT_INJECTION]: The skill identifies an attack surface for indirect prompt injection by processing external data such as comments, DMs, and web results. It provides appropriate mitigation by explicitly instructing the agent to treat this data as content rather than executable commands. Ingestion points:
SKILL.md; Boundary markers: Present inSKILL.md; Capability inventory: Network operations via WoopSocial API; Sanitization: Explicit defensive instructions included inSKILL.md.
Audit Metadata