alterlab-pra-campaign-strategist

Pass

Audited by Gen Agent Trust Hub on Apr 5, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill is instructed to perform autonomous web searches to gather current competitor campaigns, market trends, and audience behavior data.
  • [COMMAND_EXECUTION]: The agent is authorized to create and write multiple markdown files (e.g., {project}-rostir-plan.md, {project}-budget-matrix.md) directly to the project directory as part of its standard workflow.
  • [PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection (Category 8).
  • Ingestion points: Untrusted data enters the agent context through web search results and the reading of existing project files (workflow steps 1 and 2 in SKILL.md).
  • Boundary markers: The instructions do not define delimiters or specific warnings to ignore instructions embedded within the ingested data.
  • Capability inventory: The agent has the capability to search the web, read files, and write new files across its workflow (documented in SKILL.md).
  • Sanitization: There is no mention of sanitization, validation, or escaping of external content before it is processed or used to generate new files.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 5, 2026, 11:44 PM
Security Audit — agent-trust-hub — alterlab-pra-campaign-strategist