marketing-brief

Pass

Audited by Gen Agent Trust Hub on May 11, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The skill ingests untrusted content from external sources such as GitHub PR descriptions, review comments, and git logs (defined in Phase 1 of SKILL.md). This creates a surface for indirect prompt injection, where an attacker could embed malicious instructions in a PR to influence the agent's output.
  • Ingestion points: PR descriptions, PR review comments, git commit messages, and repository files (README, docs, codebase feature paths).
  • Boundary markers: The skill includes a mandatory verification step in Phase 1, Step 3, where the agent must present its understanding and wait for user confirmation before generating the brief.
  • Capability inventory: The skill can execute shell commands (gh, git), perform web searches for competitive research, and write files to the local docs/marketing/ directory.
  • Sanitization: No explicit delimiters or instructions to ignore embedded commands within the ingested text are provided in the prompt logic.
  • [COMMAND_EXECUTION]: The skill relies on executing CLI tools such as gh (GitHub CLI) and git to analyze changes. It uses commands like gh pr view, gh pr diff, git diff, and git log based on user-supplied inputs (PR numbers or git refs).
Audit Metadata
Risk Level
SAFE
Analyzed
May 11, 2026, 10:14 AM
Security Audit — agent-trust-hub — marketing-brief