marketing-pipeline
Pass
Audited by Gen Agent Trust Hub on May 11, 2026
Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [PROMPT_INJECTION]: The skill exhibits a surface for indirect prompt injection by design. It collects untrusted data from external sources and pipes it through a chain of sub-skills where the output of one serves as the input for the next.
- Ingestion points: Data enters the agent context via GitHub PRs, git ref ranges, local file/directory paths, or freeform text as defined in Step 1 of SKILL.md.
- Boundary markers: Absent. The instructions do not specify the use of delimiters or 'ignore' instructions when interpolating external data into sub-skill calls.
- Capability inventory: The orchestrator has the capability to create local directories and invoke other functional skills (e.g., /marketing-brief, /newsletter) using the Skill tool as seen in Step 2b and Step 4 of SKILL.md.
- Sanitization: Absent. There is no evidence of validation, escaping, or filtering of the content retrieved from PRs or files before it is processed by downstream skills.
- [COMMAND_EXECUTION]: The skill performs file system operations such as creating directories (e.g., 'marketing/launch-/') and saving multiple markdown and media files to specific paths. While these are intended behaviors for the skill's primary purpose, they involve direct file system interaction driven by inputs gathered during the orchestration process.
Audit Metadata