gtm-icp
Pass
Audited by Gen Agent Trust Hub on Jun 27, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: No malicious patterns, prompt injections, or unauthorized data access were identified. The skill's behavior aligns with its described purpose of marketing research and synthesis.
- [DATA_EXPOSURE]: The skill reads from and writes to the
projects/directory (gtm-context.mdandicp-personas.md). This localized file access is necessary for maintaining project context and saving results, and does not involve sensitive system paths or credentials. - [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from external web sources (e.g., G2, Reddit, LinkedIn) via parallel research sub-agents.
- Ingestion points: External websites via sub-agent research tasks in
SKILL.md(Step 2). - Boundary markers: The sub-agent prompts use structured instructions to focus on language mining and buying behavior.
- Capability inventory:
Read,Write,WebSearch, andTasktools. The primary capability is writing markdown files to the local project directory. - Sanitization: The skill relies on the synthesis step to organize research findings into a structured format before saving.
Audit Metadata