product-marketing-context

Pass

Audited by Gen Agent Trust Hub on Jun 16, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill's primary function is to consolidate project information into a marketing context document located at .claude/product-marketing-context.md. Its file access and write operations are appropriate for this task.
  • [PROMPT_INJECTION]: The skill does not contain instructions to override safety filters, extract system prompts, or disregard user guidelines. It includes an indirect injection surface by reading codebase files like READMEs; however, there is no evidence of malicious exploitation. Ingestion points: Project codebase files (README, landing pages, package.json); Boundary markers: Absent; Capability inventory: Local file read/write; Sanitization: Absent.
  • [DATA_EXFILTRATION]: No network-related tools or commands (e.g., curl, wget) are utilized, and no access to sensitive directories like .ssh or .aws is requested.
  • [REMOTE_CODE_EXECUTION]: No external package installations or remote script executions are present in the workflow.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 16, 2026, 04:25 AM
Security Audit — agent-trust-hub — product-marketing-context