brand-mention-monitor

Pass

Audited by Gen Agent Trust Hub on Aug 26, 2026

Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
  • [PROMPT_INJECTION]: The skill exhibits an attack surface for indirect prompt injection. It is designed to ingest and process untrusted content from social media platforms, forums, and news sites as defined in references/source-playbook.md.
  • Ingestion points: Content is retrieved from platforms like Reddit, X, and various news sites via web search tools.
  • Boundary markers: No explicit delimiters or instructions to ignore embedded prompts are provided for the raw ingested content.
  • Capability inventory: The skill writes extracted data and scoring history to workspace files (memory.md) and generates suggested response drafts.
  • Sanitization: The skill mitigates risks by requiring explicit human approval before any suggested actions are executed and emphasizing source verification.
  • [NO_CODE]: The skill consists entirely of instructional markdown and does not include any executable scripts, binaries, or package dependencies, which limits the potential for traditional code-based attacks.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 26, 2026, 04:27 PM
Security Audit — agent-trust-hub — brand-mention-monitor