cs-marketing-research

Pass

Audited by Gen Agent Trust Hub on Aug 17, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill consists of instructional markdown and configuration files that define a research workflow. No executable code, hidden payloads, or suspicious system commands are included.
  • [INDIRECT_PROMPT_INJECTION]: The skill instructions involve ingesting external data from product documentation and source repositories, which creates a potential surface for indirect prompt injection. However, this is inherent to the research functionality, and the instructions explicitly include safety-conscious guidance to flag credential-scraping or GUI-injection approaches.
  • Ingestion points: External product documentation, release notes, and source code repositories (SKILL.md).
  • Boundary markers: None specified in the instructions.
  • Capability inventory: Reading project context and PRDs, writing to mindmaps, and creating/updating features or tasks (SKILL.md).
  • Sanitization: No explicit sanitization or filtering steps are defined for the external content.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 17, 2026, 06:20 PM
Security Audit — agent-trust-hub — cs-marketing-research