social-media-publish
Pass
Audited by Gen Agent Trust Hub on Sep 19, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill consists solely of instructions for interacting with official social media management domains via a browser interface. It does not include any scripts, executable code, or network operations to untrusted third-party servers.
- [INDIRECT_PROMPT_INJECTION]: The skill processes user-supplied text for social media posts, which constitutes a potential surface for indirect prompt injection. Ingestion points: User-provided article titles and body content processed in SKILL.md. Boundary markers: None explicitly defined to separate untrusted content from automation instructions. Capability inventory: Browser navigation and UI interaction (clicking, typing) on platforms like mp.weixin.qq.com and baijiahao.baidu.com. Sanitization: The skill mentions automatic Markdown-to-HTML conversion but does not specify security-related sanitization or filtering of the input data.
Audit Metadata