marketing-analyst

Pass

Audited by Gen Agent Trust Hub on Sep 28, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: Analysis of the skill instructions and associated scripts indicates a focused intent on marketing data processing. The skill does not perform suspicious network operations, access sensitive system files, or attempt to bypass security controls.
  • [INDIRECT_PROMPT_INJECTION]: The skill's workflow involves reading and processing external data files, which presents a surface for indirect prompt injection if those files contain malicious instructions.
  • Ingestion points: Scripts channel_mix_optimizer.py, cohort_analyzer.py, and marketing_forecast_generator.py load data from user-supplied JSON files.
  • Boundary markers: The provided instructions lack specific directives for the agent to use delimiters or ignore potentially adversarial instructions embedded within the data sources.
  • Capability inventory: The skill is limited to data computation and stdout reporting; it does not have capabilities for network communication, file system modification, or dynamic code execution.
  • Sanitization: Input data is parsed using standard library JSON functions without additional sanitization or instruction-filtering logic.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 28, 2026, 07:26 AM
Security Audit — agent-trust-hub — marketing-analyst