marketing-social

Pass

Audited by Gen Agent Trust Hub on Aug 8, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides shell command templates in references/listening.md that utilize curl and jq to interact with public APIs for Reddit, Hacker News, and Bluesky.
  • [PROMPT_INJECTION]: The social listening workflow ingests untrusted content from external platforms, creating a potential surface for indirect prompt injection.
  • Ingestion points: Data fetched from Reddit, Hacker News, and Bluesky APIs as described in references/listening.md.
  • Boundary markers: Absent; fetched data is processed without explicit delimiters or instructions to ignore embedded commands.
  • Capability inventory: The agent analyzes external posts to generate summaries, engagement scores, and draft comment replies.
  • Sanitization: Absent; no specific validation or escaping mechanisms are provided for the external data before LLM processing.
  • [SAFE]: External references to platforms such as Reddit, YouTube, and Bluesky are to well-known services and do not involve suspicious domains.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 8, 2026, 02:46 PM
Security Audit — agent-trust-hub — marketing-social