product-marketing-context

Pass

Audited by Gen Agent Trust Hub on Apr 7, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill's primary purpose is to consolidate marketing information into a local configuration file at .agents/product-marketing-context.md. All file operations are restricted to the local project environment.
  • [PROMPT_INJECTION]: The skill processes data from the codebase (e.g., README files, package.json, marketing copy) to auto-draft context documents. This represents an indirect prompt injection surface; however, the workflow includes a mandatory user review step ('The user then reviews, corrects, and fills gaps') and focuses on generating static markdown content, which mitigates the risk of the agent executing hidden instructions.
  • [DATA_EXFILTRATION]: The skill scans project files to extract marketing context. No evidence of network operations, external requests, or data transmission was found. All gathered data is stored locally within the project folder.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 7, 2026, 03:42 AM
Security Audit — agent-trust-hub — product-marketing-context