marketing-plan
Pass
Audited by Gen Agent Trust Hub on Aug 23, 2026
Risk Level: SAFE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes external, client-supplied documentation (e.g., decks, audit reports, Slack logs) stored in the
~/marketing-plans/{client-slug}/materials/directory to synthesize marketing plans. This ingestion of untrusted data constitutes an attack surface. However, this behavior is a core functional requirement of the fractional CMO persona and is documented as part of the initial research phase. - [DATA_EXPOSURE_EXFILTRATION]: The skill facilitates the aggregation of sensitive business intelligence from services such as Stripe, Google Analytics, and Ahrefs using standard API integration patterns. It stores this state locally in a progress-tracking file and offers a user-initiated option to publish finalized documents to a GitHub repository. All data handling is within the scope of the stated professional purpose of the skill.
Audit Metadata