community-health-monitoring

Pass

Audited by Gen Agent Trust Hub on Feb 28, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it processes untrusted data from X (Twitter) profiles and tweets.
  • Ingestion points: Untrusted data enters the agent context through the x_get_followers and x_get_tweets tools mentioned in SKILL.md.
  • Boundary markers: There are no explicit boundary markers or instructions to the agent to disregard instructions embedded within the social media content.
  • Capability inventory: The skill includes scripts capable of modifying account state, such as src/blockBots.js and src/unfollowback.js.
  • Sanitization: The provided workflow does not specify any sanitization or validation steps for the content retrieved from external profiles.
Audit Metadata
Risk Level
SAFE
Analyzed
Feb 28, 2026, 09:53 AM