social-media-publish

Pass

Audited by Gen Agent Trust Hub on Sep 19, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill consists solely of instructions for interacting with official social media management domains via a browser interface. It does not include any scripts, executable code, or network operations to untrusted third-party servers.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes user-supplied text for social media posts, which constitutes a potential surface for indirect prompt injection. Ingestion points: User-provided article titles and body content processed in SKILL.md. Boundary markers: None explicitly defined to separate untrusted content from automation instructions. Capability inventory: Browser navigation and UI interaction (clicking, typing) on platforms like mp.weixin.qq.com and baijiahao.baidu.com. Sanitization: The skill mentions automatic Markdown-to-HTML conversion but does not specify security-related sanitization or filtering of the input data.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 19, 2026, 11:31 PM
Security Audit — agent-trust-hub — social-media-publish