product-marketing-context
Pass
Audited by Gen Agent Trust Hub on Apr 16, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill performs legitimate repository analysis and document creation tasks within the local workspace. Its operations are transparent and follow user-directed workflows.- [PROMPT_INJECTION]: The skill processes untrusted data from repository files during its auto-drafting phase, presenting an indirect prompt injection surface. 1. Ingestion points: The agent reads
README,package.json, and various marketing or landing page files. 2. Boundary markers: No explicit instructions are provided to use delimiters or delimiters or ignore instructions found within analyzed text. 3. Capability inventory: The skill is limited to reading repository files and writing a marketing context to.agents/product-marketing-context.md. 4. Sanitization: No explicit content filtering or validation of the ingested text is performed. Note that this is a standard risk for document-summarization features and is mitigated by the limited capabilities and user-review step.
Audit Metadata