product-marketing
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from repository files (such as README, landing pages, marketing copy, and package.json) during the auto-drafting workflow. It lacks explicit boundary markers or input sanitization mechanisms to filter out potentially malicious natural language instructions embedded within these files. However, because its capabilities are strictly limited to writing a localized markdown file (.agents/product-marketing.md) and do not involve remote code execution, command execution, or network exfiltration, the overall security risk remains safe.
Audit Metadata