creator-campaign-ops

Pass

Audited by Gen Agent Trust Hub on Jul 2, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted external data from social media platforms (X, YouTube, TikTok, Instagram), including posts, comments, and profile descriptions. This creates an attack surface where malicious instructions hidden in public social media content could attempt to manipulate the agent's behavior during the analysis or reporting phases.
  • Ingestion points: Data is retrieved via the unifapi skill from search results and specific profile/post lookups across all supported platforms (detailed in SKILL.md).
  • Boundary markers: The instructions do not specify clear delimiters or "ignore" instructions for the ingested social media content.
  • Capability inventory: The skill is strictly read-only; it performs data retrieval and analysis but does not have the capability to write files, execute shell commands, or perform network requests outside of the defined MCP toolset.
  • Sanitization: No explicit sanitization or filtering of the retrieved social media text is described in the prompt workflow.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 2, 2026, 10:28 AM
Security Audit — agent-trust-hub — creator-campaign-ops