skills/cmj-hub/claude-evp/evp/Gen Agent Trust Hub

evp

Pass

Audited by Gen Agent Trust Hub on Sep 8, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADS
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill references several external GitHub repositories belonging to the vendor (cmj-hub/claude-cold-email, cmj-hub/claude-psp, and cmj-hub/evp-generator). These are provided as documentation links for related tools and do not involve piped execution or automatic installation of untrusted scripts.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes user-supplied information about products and audiences to generate marketing copy. While this provides a surface for indirect prompt injection, the skill lacks high-privilege capabilities or network-connected tools that would make such an attack exploitable, representing a standard use case.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 8, 2026, 10:28 PM
Security Audit — agent-trust-hub — evp