marketing-sections-toolkit

Pass

Audited by Gen Agent Trust Hub on Aug 30, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The evaluation guide (EVAL.md) includes bash snippets using grep to perform static analysis on project source code. These commands are intended for auditing structural best practices and do not involve remote execution or high-privilege operations.
  • [INDIRECT_PROMPT_INJECTION]: The audit protocols ingest project source files (src) as untrusted data. Mandatory Evidence Chain: (1) Ingestion Point: EVAL.md audits the $SRC directory. (2) Boundary Markers: Absent. (3) Capability Inventory: Shell commands (grep) and browser-based JS snippets in SKILL.md and EVAL.md. (4) Sanitization: Absent. Although this creates an attack surface, the logic focuses on objective regex counts and DOM metrics, posing minimal risk.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 30, 2026, 05:49 PM
Security Audit — agent-trust-hub — marketing-sections-toolkit