marketing-context
Pass
Audited by Gen Agent Trust Hub on Sep 4, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from the repository (README, landing pages, package.json) to auto-draft marketing materials, which could be exploited to influence agent behavior through hidden instructions in those files.
- Ingestion points:
SKILL.mdinstructions for codebase scanning andscripts/context_validator.pyfor file reading. - Boundary markers: None specified in the instructions for separating external content from agent instructions.
- Capability inventory: Local file system read/write access via the agent and the included Python script.
- Sanitization: No specific filtering or escaping is applied to the content read from external files beyond regex pattern matching.
- [COMMAND_EXECUTION]: The skill includes a local script
scripts/context_validator.pyintended to be executed by the agent to score marketing documents. - The script uses standard Python libraries (
re,pathlib,json) to perform its analysis and does not initiate network connections, execute arbitrary shell commands, or perform privilege escalation.
Audit Metadata