alterlab-pra-campaign-strategist
Pass
Audited by Gen Agent Trust Hub on Apr 5, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill is instructed to perform autonomous web searches to gather current competitor campaigns, market trends, and audience behavior data.
- [COMMAND_EXECUTION]: The agent is authorized to create and write multiple markdown files (e.g.,
{project}-rostir-plan.md,{project}-budget-matrix.md) directly to the project directory as part of its standard workflow. - [PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection (Category 8).
- Ingestion points: Untrusted data enters the agent context through web search results and the reading of existing project files (workflow steps 1 and 2 in SKILL.md).
- Boundary markers: The instructions do not define delimiters or specific warnings to ignore instructions embedded within the ingested data.
- Capability inventory: The agent has the capability to search the web, read files, and write new files across its workflow (documented in SKILL.md).
- Sanitization: There is no mention of sanitization, validation, or escaping of external content before it is processed or used to generate new files.
Audit Metadata