facebook-marketing
Pass
Audited by Gen Agent Trust Hub on Sep 25, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill instructions provide legitimate marketing strategies and code templates for the Facebook Graph API.
- [EXTERNAL_DOWNLOADS]: The skill interacts with official Facebook domains (graph.facebook.com and www.facebook.com), which are well-known services associated with the skill's primary purpose.
- [INDIRECT_PROMPT_INJECTION]: The skill includes an attack surface by processing user-provided prompts (e.g., brand names or campaign details in SKILL.md examples) and interpolating them into generated scripts or plans. While explicit boundary markers and sanitization are absent, the risk is minimal as capabilities are restricted to standard API interactions with trusted services. Evidence: Ingestion points: User prompts in Example 1 and 2. Boundary markers: Absent. Capability inventory: network operations via fetch to Facebook Graph API. Sanitization: Absent.
Audit Metadata