xpoz-social-tracking

Pass

Audited by Gen Agent Trust Hub on Jun 22, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: The skill exhibits a potential surface for indirect prompt injection as it is designed to ingest and process untrusted data from external social media platforms (Twitter, Reddit, TikTok, Instagram).
  • Ingestion points: Social media posts and metadata retrieved via xpoz-cli and Xpoz SDKs.
  • Boundary markers: The instructions lack explicit delimiters to isolate retrieved external content from the agent's internal control logic.
  • Capability inventory: The agent uses xpoz-cli and SDKs to manage tracking configurations.
  • Sanitization: There are no explicit instructions for the agent to sanitize or validate the content of tracked social media items before processing.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 22, 2026, 07:41 AM
Security Audit — agent-trust-hub — xpoz-social-tracking