gtm-executor

Pass

Audited by Gen Agent Trust Hub on Sep 13, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external business artifacts and market research data, which creates a potential surface for indirect prompt injection attacks where malicious instructions could be embedded in the ingested content.\n
  • Ingestion points: The workflow ingests customer segments from BM-XXXX, market research from GTM-XXXX, and market observations from OBS-XXXX.\n
  • Boundary markers: The instructions do not specify any delimiters or explicit boundary markers to separate the external market data from the agent's operational instructions.\n
  • Capability inventory: The agent has the capability to write output files (GTM plans, channel strategies, launch plans, etc.) to the .agile-v/business/ directory.\n
  • Sanitization: No explicit sanitization or filtering protocols are defined for the input data before it is used to generate marketing claims or growth hypotheses.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 13, 2026, 06:07 AM
Security Audit — agent-trust-hub — gtm-executor