marketing-influencer-marketing
Pass
Audited by Gen Agent Trust Hub on Sep 2, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to fetch and analyze external social media content, audience comments, and creator media kits, which creates a potential surface for indirect prompt injection from untrusted data sources.
- Ingestion points: External influencer content, audience comments, and media kits processed during vetting and style analysis (referenced in
SKILL.mdandreferences/ugc-creator-program.md). - Boundary markers: The instructions do not specify the use of delimiters or specific markers to isolate external data from the system prompt.
- Capability inventory: The skill uses tools for social media fetching and video analysis (
social-fetch,watch-video) to process untrusted external data. - Sanitization: No explicit sanitization or filtering logic is provided for the content retrieved from external sources.
- [SAFE]: The skill mentions and recommends several well-known and established marketing tools and services for audience intelligence and creator discovery, such as SparkToro, Modash, GRIN, Aspire, Upfluence, and Passionfroot. These references are documented neutrally as part of the intended marketing workflow.
- [SAFE]: The skill includes a robust section on legal compliance, emphasizing the necessity of FTC disclosure (#ad) and warning against non-compliant practices like paid comment seeding. This serves as a safety guardrail for the agent's behavior.
Audit Metadata