youtube-long-form

Pass

Audited by Gen Agent Trust Hub on Jul 16, 2026

Risk Level: SAFEDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill's instructions and reference files contain no evidence of malicious code, obfuscation, or unauthorized access. All identified external resources are either vendor-owned or well-known services.
  • [DATA_EXFILTRATION]: The skill references network endpoints at api.woopsocial.com for content scheduling. These endpoints are vendor-owned resources for the author 'social-media-skills' and are used for their declared purpose.
  • [PROMPT_INJECTION]: The skill identifies an attack surface for indirect prompt injection by processing external data such as comments, DMs, and web results. It provides appropriate mitigation by explicitly instructing the agent to treat this data as content rather than executable commands. Ingestion points: SKILL.md; Boundary markers: Present in SKILL.md; Capability inventory: Network operations via WoopSocial API; Sanitization: Explicit defensive instructions included in SKILL.md.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 16, 2026, 06:02 PM
Security Audit — agent-trust-hub — youtube-long-form