product-marketing-context

Pass

Audited by Gen Agent Trust Hub on Apr 26, 2026

Risk Level: SAFENO_CODE
Full Analysis
  • [SAFE]: The skill manages product positioning data by reading local project files such as READMEs and package.json. It operates within the local file system and does not perform network operations or access sensitive credentials.
  • [SAFE]: A surface for indirect prompt injection exists because the skill processes untrusted text from the codebase; however, this is mitigated by a mandatory human review step before any data is saved to disk.
  • Ingestion points: Local codebase files (README, marketing copy, etc.) as specified in SKILL.md Step 2.
  • Boundary markers: Explicit instructions to present the draft for user review and correction before saving.
  • Capability inventory: File-read access to the codebase and file-write access to the .agents/ directory.
  • Sanitization: The skill performs summarization into a markdown template without specific character escaping.
  • [NO_CODE]: This skill consists of natural language instructions and evaluation configurations, without any bundled scripts, binaries, or external code dependencies.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 26, 2026, 10:15 PM
Security Audit — agent-trust-hub — product-marketing-context