marketing-pipeline-automated-content

Pass

Audited by Gen Agent Trust Hub on Jun 12, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The instructions guide users to clone the repository 'https://github.com/pennydinh/marketing-pineline-share.git' and execute 'npm install'. This process downloads and prepares for execution code from a repository that is not part of the established trusted organizations.- [PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection due to its core functionality. * Ingestion points: The 'crawlNews' function fetches data from external, third-party sites including Twitter, TechCrunch, and LinkedIn as seen in 'SKILL.md'. * Boundary markers: The provided code snippets do not include delimiters or instructions to the AI to ignore potentially malicious embedded content within the research data. * Capability inventory: The agent has the ability to generate text content and render videos based on the analyzed research. * Sanitization: There is no evidence of data sanitization or filtering before the external content is processed by the AI models.- [COMMAND_EXECUTION]: The troubleshooting documentation includes the command 'sudo apt-get install ffmpeg', which is a standard procedure for installing necessary system dependencies for video rendering.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 12, 2026, 07:44 PM
Security Audit — agent-trust-hub — marketing-pipeline-automated-content