post-writer-sms
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to read and process data from a local file to determine tone and voice, creating a potential vector for malicious instruction injection.
- Ingestion points: The agent is instructed to read content from
.agents/social-media-context-sms.mdat skill load time. - Capability inventory: The skill utilizes the
create_posttool within the BlackTwist MCP environment to publish content to social media platforms. - Boundary markers: There are no explicit delimiters or instructions provided to ensure the agent ignores any embedded commands or formatting overrides within the context file.
- Sanitization: The skill does not define any validation or sanitization steps for the data retrieved from the context file before it is used to influence the agent's output.
Audit Metadata