content-opportunity-brief

Pass

Audited by Gen Agent Trust Hub on Jul 2, 2026

Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [PROMPT_INJECTION]: The skill processes untrusted text from external sources such as Reddit comments and social media posts, which constitutes an indirect prompt injection surface where malicious data could influence agent output. (1) Ingestion points: Data retrieved via UnifAPI endpoints for Reddit, X, YouTube, and TikTok (SKILL.md). (2) Boundary markers: No explicit delimiters are used to wrap external content. (3) Capability inventory: The skill is restricted to reading public data and project context (SKILL.md). (4) Sanitization: No content validation or sanitization is mentioned.
  • [EXTERNAL_DOWNLOADS]: The README instructs users to install the skill via npx skills add unifapi-agent/agents, which downloads and runs code from the vendor's repository.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 2, 2026, 10:29 AM
Security Audit — agent-trust-hub — content-opportunity-brief