marketing-campaigns

Pass

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • Indirect Prompt Injection Surface: The skill processes information retrieved from external tools such as get_campaign_performance and get_listing. This identifies a potential surface where external data could influence agent behavior. (1) Ingestion points: Data retrieved via get_campaign_performance and get_listing in SKILL.md. (2) Boundary markers: The instructions lack specific delimiters or instructions to ignore instructions embedded in data. (3) Capability inventory: The skill can stage campaign changes (stage_campaign) and present data (present_metrics). (4) Sanitization: No explicit data sanitization or validation steps are defined for external content.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 21, 2026, 12:15 AM
Security Audit — agent-trust-hub — marketing-campaigns