stelow-product-promotions
Pass
Audited by Gen Agent Trust Hub on Sep 8, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill describes a workflow mode where the agent is instructed to execute a local script
scripts/stelowto advance the process state. This script appears to be a local utility belonging to the vendor's framework. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to process untrusted user input concerning product launch details to generate marketing plans.
- Ingestion points: User-provided inputs regarding course launches and promotion goals in SKILL.md.
- Boundary markers: None are defined to separate user data from the agent's instructions.
- Capability inventory: The skill uses file read/write permissions and executes a local script (
scripts/stelow) as part of its workflow. - Sanitization: No explicit input sanitization or validation routines are specified.
Audit Metadata