marketing-brief
Pass
Audited by Gen Agent Trust Hub on May 11, 2026
Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [PROMPT_INJECTION]: The skill ingests untrusted content from external sources such as GitHub PR descriptions, review comments, and git logs (defined in Phase 1 of SKILL.md). This creates a surface for indirect prompt injection, where an attacker could embed malicious instructions in a PR to influence the agent's output.
- Ingestion points: PR descriptions, PR review comments, git commit messages, and repository files (README, docs, codebase feature paths).
- Boundary markers: The skill includes a mandatory verification step in Phase 1, Step 3, where the agent must present its understanding and wait for user confirmation before generating the brief.
- Capability inventory: The skill can execute shell commands (
gh,git), perform web searches for competitive research, and write files to the localdocs/marketing/directory. - Sanitization: No explicit delimiters or instructions to ignore embedded commands within the ingested text are provided in the prompt logic.
- [COMMAND_EXECUTION]: The skill relies on executing CLI tools such as
gh(GitHub CLI) andgitto analyze changes. It uses commands likegh pr view,gh pr diff,git diff, andgit logbased on user-supplied inputs (PR numbers or git refs).
Audit Metadata