instagram-expert
Pass
Audited by Gen Agent Trust Hub on Apr 20, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill functions solely as a knowledge base and guide for the Instagram platform. No malicious instructions, commands, or data exfiltration techniques were found in the instructions or reference files.
- [PROMPT_INJECTION]: The skill describes APIs for retrieving user-generated content such as comments and mentions in 'references/insights-comments-api.md'. This exposes an indirect prompt injection surface if an agent uses these instructions to process untrusted data. Mandatory Evidence: 1. Ingestion points: Media comments and mentions nodes in 'references/insights-comments-api.md'. 2. Boundary markers: None provided in the reference documentation. 3. Capability inventory: Comment management (reply, hide, delete) and business discovery in 'references/insights-comments-api.md'. 4. Sanitization: None described in the documentation. This is a characteristic risk of social media integration rather than a malicious finding in the skill itself.
Audit Metadata