stelow-product-promotions

Pass

Audited by Gen Agent Trust Hub on Sep 8, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill describes a workflow mode where the agent is instructed to execute a local script scripts/stelow to advance the process state. This script appears to be a local utility belonging to the vendor's framework.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to process untrusted user input concerning product launch details to generate marketing plans.
  • Ingestion points: User-provided inputs regarding course launches and promotion goals in SKILL.md.
  • Boundary markers: None are defined to separate user data from the agent's instructions.
  • Capability inventory: The skill uses file read/write permissions and executes a local script (scripts/stelow) as part of its workflow.
  • Sanitization: No explicit input sanitization or validation routines are specified.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 8, 2026, 03:01 AM
Security Audit — agent-trust-hub — stelow-product-promotions