solo-community-outreach

Pass

Audited by Gen Agent Trust Hub on Feb 26, 2026

Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [PROMPT_INJECTION]: Indirect Prompt Injection Surface
  • Ingestion points: Thread titles, URLs, and comment counts from Reddit, Hacker News, and ProductHunt (fetched via WebSearch, WebFetch, or the web_search MCP tool in Step 3).
  • Boundary markers: Absent; the skill does not define specific delimiters or instructions to ignore embedded commands when processing external web content for the outreach plan.
  • Capability inventory: Uses Write tool to save a generated plan to docs/outreach-plan.md. No direct code execution capabilities (exec/eval) are present.
  • Sanitization: Absent; the skill drafts responses directly from the fetched data without specific filtering or escaping logic for the external content.
  • [EXTERNAL_DOWNLOADS]: Reference to external repository
  • Evidence: The documentation suggests setting up a self-hosted search adapter located at github.com/fortunto2/searxng-docker-tavily-adapter to improve search results.
  • Status: This is a vendor-owned resource belonging to the author (fortunto2). It is documented as an optional manual setup and is not automatically downloaded or executed by the skill's code.
Audit Metadata
Risk Level
SAFE
Analyzed
Feb 26, 2026, 01:42 PM