gtm-launch-planner

Pass

Audited by Gen Agent Trust Hub on Aug 30, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests data from several untrusted external sources, creating a surface for indirect prompt injection. Malicious instructions embedded in these sources could potentially influence the agent's output or behavior.
  • Ingestion points: The skill collects data from YouTube comments (youtube_comments), job postings (google_jobs), and web-scraped content from community forums like Reddit and Hacker News (web_scrape) as detailed in SKILL.md (Step 2) and references/scrapingdog-tools.md.
  • Boundary markers: The instructions do not define specific delimiters or "ignore instructions" warnings to separate untrusted data from the agent's system prompts.
  • Capability inventory: The skill's capabilities are limited to research and report generation (creating an HTML artifact). It does not include high-risk capabilities such as arbitrary shell execution, system-level file writes, or network operations to non-standard domains beyond the provided research tools.
  • Sanitization: There is no mention of sanitizing or filtering the ingested content before it is processed or included in the final report.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 30, 2026, 08:07 PM
Security Audit — agent-trust-hub — gtm-launch-planner