marketing-social-pulse

Pass

Audited by Gen Agent Trust Hub on Apr 16, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill includes a preamble bash script that searches local directories ($HOME/kaito-skills, $HOME/.claude/skills/, etc.) and executes a version check binary (kaito-skills-update-check). This is a standard mechanism for skill maintenance for the MetaSearch-IO/Kaito suite.
  • [PROMPT_INJECTION]: The skill processes untrusted content from social media platforms (Twitter) via MCP tools, creating a potential surface for indirect prompt injection. 1. Ingestion points: Data retrieved from kaito_advanced_search and kaito_mentions. 2. Boundary markers: Absent. No specific instructions are provided to the agent to treat external data as untrusted. 3. Capability inventory: The skill uses Kaito-specific MCP tools for data retrieval and does not possess high-risk capabilities like arbitrary file writing or unauthorized network access. 4. Sanitization: No sanitization or filtering of the retrieved content is performed.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 16, 2026, 08:54 AM