marketing-plan

Pass

Audited by Gen Agent Trust Hub on Aug 23, 2026

Risk Level: SAFE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external, client-supplied documentation (e.g., decks, audit reports, Slack logs) stored in the ~/marketing-plans/{client-slug}/materials/ directory to synthesize marketing plans. This ingestion of untrusted data constitutes an attack surface. However, this behavior is a core functional requirement of the fractional CMO persona and is documented as part of the initial research phase.
  • [DATA_EXPOSURE_EXFILTRATION]: The skill facilitates the aggregation of sensitive business intelligence from services such as Stripe, Google Analytics, and Ahrefs using standard API integration patterns. It stores this state locally in a progress-tracking file and offers a user-initiated option to publish finalized documents to a GitHub repository. All data handling is within the scope of the stated professional purpose of the skill.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 23, 2026, 11:27 PM
Security Audit — agent-trust-hub — marketing-plan