marketing-claims-review

Pass

Audited by Gen Agent Trust Hub on May 15, 2026

Risk Level: SAFEPROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
  • [PROMPT_INJECTION]: Indirect Prompt Injection Surface. The skill is designed to ingest and process untrusted marketing copy provided by users, which creates a risk of embedded instructions influencing the agent's behavior.
  • Ingestion points: User-pasted marketing copy or file paths provided via the argument hint (SKILL.md).
  • Boundary markers: Absent. The instructions do not define clear delimiters or specific instructions for the agent to ignore commands contained within the analyzed marketing text.
  • Capability inventory: The skill performs file read/write operations to specific plugin directories (~/.claude/plugins/config/...) and utilizes web search or legal research tools (SKILL.md).
  • Sanitization: Absent. There are no instructions for sanitizing or validating the input text before processing.
  • [DATA_EXFILTRATION]: Potential Data Exposure. The skill allows users to provide file paths via the argument-hint. While the instructions target specific plugin directories, this input mechanism could be exploited to attempt reading sensitive local files if the underlying platform does not strictly sandbox file system access.
Audit Metadata
Risk Level
SAFE
Analyzed
May 15, 2026, 07:06 AM
Security Audit — agent-trust-hub — marketing-claims-review