curating-user-generated-content
Warn
Audited by Gen Agent Trust Hub on Feb 16, 2026
Risk Level: MEDIUMPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION] (MEDIUM): The skill is susceptible to indirect prompt injection via untrusted social media content. Ingestion points: Content is retrieved from platforms like Instagram, TikTok, and Reddit using hashtags and brand mentions as detailed in Step 2 of SKILL.md. Boundary markers: The instructions lack delimiters or specific directives to ignore instructions that may be hidden in the user-generated content. Capability inventory: The agent generates reports and content drafts for external distribution based on this data. Sanitization: No logic is provided to sanitize or validate the content before it is processed or repurposed.
Audit Metadata