growth-marketer

Pass

Audited by Gen Agent Trust Hub on May 1, 2026

Risk Level: SAFE
Full Analysis
  • [DYNAMIC_CONTEXT_INJECTION]: The skill uses the !command syntax to execute shell commands (cat) at load time to pull in protocol files and configuration files such as .production-grade.yaml and .forgewright/settings.md. These operations are used to provide the agent with necessary context and do not involve untrusted input or sensitive system paths.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze external data, including competitor URLs and product documentation (BRD/PRD). While this creates a surface for indirect prompt injection where instructions hidden in a website or document could influence the agent, the skill follows standard marketing workflows.
  • Ingestion points: External URLs, competitor websites, and product requirement documents.
  • Boundary markers: None explicitly defined in the instructions.
  • Capability inventory: File system writes to the marketing/ directory.
  • Sanitization: No specific sanitization or filtering of external content is described.
Audit Metadata
Risk Level
SAFE
Analyzed
May 1, 2026, 08:02 AM
Security Audit — agent-trust-hub — growth-marketer