growth-marketer
Pass
Audited by Gen Agent Trust Hub on May 1, 2026
Risk Level: SAFE
Full Analysis
- [DYNAMIC_CONTEXT_INJECTION]: The skill uses the
!commandsyntax to execute shell commands (cat) at load time to pull in protocol files and configuration files such as.production-grade.yamland.forgewright/settings.md. These operations are used to provide the agent with necessary context and do not involve untrusted input or sensitive system paths. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze external data, including competitor URLs and product documentation (BRD/PRD). While this creates a surface for indirect prompt injection where instructions hidden in a website or document could influence the agent, the skill follows standard marketing workflows.
- Ingestion points: External URLs, competitor websites, and product requirement documents.
- Boundary markers: None explicitly defined in the instructions.
- Capability inventory: File system writes to the
marketing/directory. - Sanitization: No specific sanitization or filtering of external content is described.
Audit Metadata