content-strategy
Pass
Audited by Gen Agent Trust Hub on Jul 3, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: An indirect prompt injection surface is present due to the processing of untrusted data from external social media platforms.
- Ingestion points: The skill ingests Reddit comments, YouTube titles/descriptions, and TikTok metadata via the
unifapitoolset. - Boundary markers: No specific delimiters or instructions are provided to the agent to disregard instructions potentially hidden within the scraped social media content.
- Capability inventory: The skill is explicitly defined as "read-only" and "eyes not hands." It lacks any tools for file system modification, shell command execution, or network exfiltration of local data.
- Sanitization: External content is interpolated directly into a markdown report without explicit escaping or sanitization logic.
- [EXTERNAL_DOWNLOADS]: The skill fetches public market research data from UnifAPI, which is a resource owned by the skill's author (
unifapi-agent). - [COMMAND_EXECUTION]: No executable code, shell commands, or subprocess patterns were identified in the skill files.
Audit Metadata