creator-campaign-ops

Pass

Audited by Gen Agent Trust Hub on Jul 3, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: The skill ingests data from external social media platforms (X, YouTube, TikTok, Instagram) via UnifAPI, which creates a surface for indirect prompt injection.
  • Ingestion points: Social media posts, comments, and profiles retrieved through the unifapi skill.
  • Boundary markers: No explicit delimiters or instructions are provided to the agent to ignore embedded commands in the ingested data.
  • Capability inventory: The skill is restricted to read-only research and drafting operating packs; it does not have capabilities for command execution, file modification, or outbound network requests beyond data retrieval.
  • Sanitization: No specific sanitization or filtering of external content is documented.
  • [EXTERNAL_DOWNLOADS]: Installation instructions utilize the vendor's official plugin marketplace and domain (unifapi.com), which are recognized as authorized vendor resources.
  • [DATA_EXFILTRATION]: The skill accesses local project context files, such as .agents/product-marketing.md, to inform its campaign planning. This access is confined to the local environment and is necessary for the skill's stated marketing purpose.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 3, 2026, 04:06 PM
Security Audit — agent-trust-hub — creator-campaign-ops