social-media-manager
Pass
Audited by Gen Agent Trust Hub on Sep 19, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill provides features for 'Interaction Management' and 'Data Analysis' across platforms like Zhihu, Weibo, and Twitter. This involves processing external, user-generated content which could contain malicious instructions designed to influence the agent.
- Ingestion points: The skill ingests untrusted data from external social media platforms when performing interaction management and data analysis tasks.
- Boundary markers: There are no explicit boundary markers or instructions to ignore embedded commands within the ingested platform data.
- Capability inventory: The agent has the capability to write to the file system and perform network operations through the
clawhub social postandclawhub social schedulecommands. - Sanitization: The instructions do not specify any sanitization or filtering logic for data retrieved from external platforms before it is processed by the AI.
- [EXTERNAL_DOWNLOADS]: The skill README instructs the user to install a package using
npx clawhub@latest install social-media-manager. While this is a standard installation pattern for this platform, the package name 'social-media-manager' is generic.
Audit Metadata