cs-marketing-research
Pass
Audited by Gen Agent Trust Hub on Aug 17, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill consists of instructional markdown and configuration files that define a research workflow. No executable code, hidden payloads, or suspicious system commands are included.
- [INDIRECT_PROMPT_INJECTION]: The skill instructions involve ingesting external data from product documentation and source repositories, which creates a potential surface for indirect prompt injection. However, this is inherent to the research functionality, and the instructions explicitly include safety-conscious guidance to flag credential-scraping or GUI-injection approaches.
- Ingestion points: External product documentation, release notes, and source code repositories (SKILL.md).
- Boundary markers: None specified in the instructions.
- Capability inventory: Reading project context and PRDs, writing to mindmaps, and creating/updating features or tasks (SKILL.md).
- Sanitization: No explicit sanitization or filtering steps are defined for the external content.
Audit Metadata