form-social
Pass
Audited by Gen Agent Trust Hub on Jul 1, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: Indirect Prompt Injection Surface. The skill is designed to ingest and process untrusted user-provided content (campaign goals, messages, and brand assets) and possesses capabilities to interact with external web content.
- Ingestion points: User-supplied campaign goals and verbatim copy in SKILL.md (Phase 1).
- Boundary markers: Absent; there are no instructions to ignore embedded commands in processed data.
- Capability inventory: WebFetch, WebSearch, Bash, Write, and Edit tools are available to the agent.
- Sanitization: Absent; no validation or escaping of user input is specified.
- [SAFE]: Versioning Inconsistency. The version specified in the SKILL.md frontmatter (0.6.4) does not match the version defined in the plugin.json metadata (1.9.1).
- [SAFE]: External References. The skill references external resources such as 'docs/output-kit.md' and the command '/atlas-report' which are not included in the provided skill files.
Audit Metadata