skills/airtable/skills/marketing-ops/Gen Agent Trust Hub

marketing-ops

Pass

Audited by Gen Agent Trust Hub on Jun 14, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: No malicious patterns such as credential theft, persistence, or unauthorized command execution were detected. The skill instructions are consistent with the stated purpose of marketing operations management and originate from a known vendor.
  • [DATA_EXFILTRATION]: The skill references integrations with well-known technology companies and cloud services (e.g., Salesforce, HubSpot, Vercel, Slack) and official Airtable domains. There is no evidence of data being sent to suspicious, untrusted, or unknown external endpoints.
  • [PROMPT_INJECTION]: The instructions do not contain attempts to override agent safety guidelines, extract system prompts, or bypass content filters.
  • [REMOTE_CODE_EXECUTION]: No remote code execution patterns were found. Mentions of external application deployment (e.g., custom apps on Vercel) are descriptive of user-directed development workflows and do not involve the agent executing untrusted remote scripts.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process untrusted data from marketing requests and influencer pitches.
  • Ingestion points: Marketing Requests table via intake forms (documented in SKILL.md and references/sub-workflows.md).
  • Boundary markers: Not explicitly defined in the schema, though the skill recommends using structured fields.
  • Capability inventory: MCP tools for reading and writing Airtable records (e.g., list_records_for_table, update_records_for_table).
  • Sanitization: The skill explicitly mandates a 'copilot pattern' (AI drafts followed by human review) as a primary mitigation against the automated execution of potentially malicious instructions embedded in user data.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 14, 2026, 10:47 AM
Security Audit — agent-trust-hub — marketing-ops