crawling-social-media

Pass

Audited by Gen Agent Trust Hub on Jul 4, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill content, including its instructions and metadata, does not contain any detected malicious patterns, obfuscation, hardcoded credentials, or unauthorized command execution. The workflow is consistent with the stated purpose of social media content extraction.\n- [PROMPT_INJECTION]: The skill processes untrusted metadata (such as titles, descriptions, and tags) from external social media platforms, creating a potential surface for indirect prompt injection. Evidence Chain: (1) Ingestion points: Results from getCrawlTaskStatus in SKILL.md. (2) Boundary markers: No delimiters or instructions to ignore embedded commands are present in the processing logic. (3) Capability inventory: Example 3 in SKILL.md shows data being passed to 'content' and 'publish' skills for further action. (4) Sanitization: No sanitization or validation of the scraped content is described.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 4, 2026, 05:25 AM
Security Audit — agent-trust-hub — crawling-social-media