cmo-advisor
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process external data files including CSV, JSON, and YAML formats (e.g., leads.csv, marketing_data.json). This creates a vulnerability surface where malicious instructions embedded within the data fields of these files could be processed and then reflected in the reports generated by the scripts, potentially influencing the agent's future actions.
- Ingestion points: Data files processed by brand_health_tracker.py, channel_mix_optimizer.py, and marketing_roi_calculator.py, as well as referenced files leads.csv and topics.yaml in SKILL.md.
- Boundary markers: No explicit delimiters or "ignore instructions" markers are defined for the processed data.
- Capability inventory: Execution of local analysis scripts and generation of performance reports which the agent is instructed to audit.
- Sanitization: The provided Python scripts do not perform sanitization or instruction-filtering on the input data fields before including them in the output reports.
Audit Metadata