campaign-analytics

Pass

Audited by Gen Agent Trust Hub on Sep 28, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill implements deterministic marketing analytics (attribution, funnel, and ROI) using local Python scripts.
  • All scripts (attribution_analyzer.py, funnel_analyzer.py, campaign_roi_calculator.py) utilize only the Python standard library.
  • No network operations (curl, wget, requests), file-write capabilities, or remote code execution patterns were identified.
  • Data processing is limited to mathematical modeling and generating human-readable or structured JSON summaries based on user-provided input files.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests user-provided JSON data for analysis, creating a potential surface for indirect injection if the resulting analysis is subsequently processed by an AI agent.
  • Ingestion points: Data is loaded from local JSON files via json.load() in all analysis scripts.
  • Boundary markers: The scripts validate input structure by checking for specific keys (e.g., journeys, funnel, campaigns) and exit with errors if the schema is mismatched.
  • Capability inventory: The scripts have no capabilities for network access, file system modification, or command execution. They only perform data transformation and output results to stdout.
  • Sanitization: Input is parsed as structured JSON, and numeric calculations are performed using standard arithmetic, limiting the risk of processing malicious command-like strings.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 28, 2026, 07:26 AM
Security Audit — agent-trust-hub — campaign-analytics