marketing-studio-agent

Warn

Audited by Gen Agent Trust Hub on Jul 10, 2026

Risk Level: MEDIUMEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: Clones logic from an external repository (github.com/ucsandman/marketing-studio.git) that is not owned by the skill author or a recognized trusted organization. \n- [REMOTE_CODE_EXECUTION]: Orchestrates the execution of downloaded scripts including node scripts/install-skills.mjs and python launch.py as part of the toolchain setup. \n- [COMMAND_EXECUTION]: Performs system operations such as repository cloning, dependency installation via npm install, and environment modification to link skills to the agent. \n- [REMOTE_CODE_EXECUTION]: Implements dynamic file loading using require with template strings for brand configurations, which introduces a potential path manipulation risk if inputs are not strictly controlled.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Jul 10, 2026, 04:20 PM
Security Audit — agent-trust-hub — marketing-studio-agent