solo-community-outreach
Pass
Audited by Gen Agent Trust Hub on Feb 26, 2026
Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [PROMPT_INJECTION]: Indirect Prompt Injection Surface
- Ingestion points: Thread titles, URLs, and comment counts from Reddit, Hacker News, and ProductHunt (fetched via
WebSearch,WebFetch, or theweb_searchMCP tool in Step 3). - Boundary markers: Absent; the skill does not define specific delimiters or instructions to ignore embedded commands when processing external web content for the outreach plan.
- Capability inventory: Uses
Writetool to save a generated plan todocs/outreach-plan.md. No direct code execution capabilities (exec/eval) are present. - Sanitization: Absent; the skill drafts responses directly from the fetched data without specific filtering or escaping logic for the external content.
- [EXTERNAL_DOWNLOADS]: Reference to external repository
- Evidence: The documentation suggests setting up a self-hosted search adapter located at
github.com/fortunto2/searxng-docker-tavily-adapterto improve search results. - Status: This is a vendor-owned resource belonging to the author (
fortunto2). It is documented as an optional manual setup and is not automatically downloaded or executed by the skill's code.
Audit Metadata