community-radar
Pass
Audited by Gen Agent Trust Hub on Jul 28, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: Indirect prompt injection vulnerability. The skill ingests untrusted data from platforms like LinkedIn, X, and Reddit via Apify actors or webhooks. This data is used to classify sentiment and draft replies, creating a surface where an attacker could embed instructions in a post to override the agent's logic or misuse its tools.
- Ingestion points: Social media mentions provided by external scraping tools or webhooks.
- Boundary markers: Absent; instructions do not require delimiters or ignore-embedded-instructions warnings for external content.
- Capability inventory:
swan-update-skill(modifies own instructions),swan-enrich-contact,hubspot-create-task,slack-send-notification, andswan-execute-code(reads tool output from files). - Sanitization: Absent; mentions are processed without validation or escaping.
Audit Metadata