social-publisher
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests filenames from Google Drive and interpolates them directly into prompts for caption generation, creating a surface for indirect prompt injection if a file is maliciously named.\n
- Ingestion points: File metadata (filename) from Google Drive.\n
- Boundary markers: Absent; the templates (e.g., 'Create a TikTok caption for video: {filename}') lack delimiters or instructions to ignore instructions embedded in the filename.\n
- Capability inventory: Access to multi-platform publishing tools (TikTok, Instagram, YouTube, LinkedIn, Twitter) and Slack notification capabilities.\n
- Sanitization: None; the skill does not explicitly validate or sanitize the filename before processing.\n- [DATA_EXPOSURE_AND_EXFILTRATION]: The skill interacts with common social media services and project management tools (Airtable, Slack, Google Drive) which is consistent with its stated purpose of marketing automation. No sensitive file paths or hardcoded credentials were detected.\n- [REMOTE_CODE_EXECUTION]: No patterns for remote script execution or unverifiable dependency installations were found.\n- [OBFUSCATION]: The skill uses clear, human-readable YAML and Markdown with no evidence of encoding or hidden characters.\n- [DYNAMIC_CONTEXT_INJECTION]: The skill does not utilize the '!' dynamic context execution syntax.
Audit Metadata