skills/appeeky/aso-skills/ua-campaign/Gen Agent Trust Hub

ua-campaign

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to ingest external data, creating a potential surface for indirect prompt injection if the source file is compromised.
  • Ingestion points: The skill instructions in 'Initial Assessment' require the agent to read app-marketing-context.md for context.
  • Boundary markers: The skill lacks explicit instructions or delimiters to isolate content from app-marketing-context.md or to ignore potential instructions embedded within it.
  • Capability inventory: While the skill itself does not define custom scripts, it relies on the agent's default tools to execute the marketing plan. The impact is limited to persona manipulation or misleading advice without further tool definitions.
  • Sanitization: There are no verification steps or sanitization protocols mentioned for the content of the marketing context file.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 01:32 PM
Security Audit — agent-trust-hub — ua-campaign