cohort-de-marketing-claude-skills
Pass
Audited by Gen Agent Trust Hub on Jun 29, 2026
Risk Level: SAFE
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill instructions provide guidance to clone the project repository from
github.com/marketingLendario/cohort-de-marketing.git, which is the official host for these tools. - [CREDENTIALS_UNSAFE]: The documentation describes setting up API keys for Meta, Google Ads, OpenAI, and Serper using a
.envfile, which is a standard and secure practice for secret management in agent environments. - [DATA_EXFILTRATION]: Network operations to search engines and ad libraries are performed to gather marketing insights, which is the primary declared purpose of the skill and does not constitute unauthorized data transfer.
- [PROMPT_INJECTION]: The skill ingests untrusted data from external sources like competitor ads and social media reviews, creating a surface for indirect prompt injection.
- Ingestion points: Competitor intelligence data and trend research fetched from social platforms.
- Boundary markers: None specified within the skill instructions.
- Capability inventory: File system writing operations for generating MD, HTML, PDF, and DOCX reports.
- Sanitization: No explicit logic for sanitization or filtering of external content was found.
Audit Metadata