marketing-council

Pass

Audited by Gen Agent Trust Hub on Jul 27, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: No hardcoded credentials or sensitive file access patterns (such as SSH keys or AWS configs) were identified. The skill reads local project context files like .agents/product-marketing.md which is a standard and safe practice for providing project-specific background to an agent.- [SAFE]: The skill does not contain any remote code execution (RCE) vectors. It performs research using standard agent tools (e.g., web search, deep-research) to fetch information from primary sources, following the [TRUST-SCOPE-RULE] for well-known informational services.- [SAFE]: There is no evidence of obfuscation. All instructions, reference dossiers, and templates are written in clear, human-readable markdown and JSON without the use of Base64, zero-width characters, or homoglyph attacks.- [SAFE]: The risk of indirect prompt injection is mitigated by the skill's explicit grounding rules, which mandate that every take must be grounded in documented frameworks and labeled as a simulation, reducing the likelihood of malicious external content overriding the agent's core instructions.- [SAFE]: No persistence mechanisms, privilege escalation commands, or dynamic execution patterns were found. The custom advisor feature uses a standard template and requires user-provided data, avoiding the invention of heuristics for private individuals.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 27, 2026, 12:30 AM
Security Audit — agent-trust-hub — marketing-council