marketing-research-posting-plan
Pass
Audited by Gen Agent Trust Hub on Apr 18, 2026
Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
- [PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection due to its core requirement to ingest untrusted web data.
- Ingestion points: The workflow mandates browsing Reddit, forums, and GitHub discussions, which are attacker-controllable sources.
- Boundary markers: The instructions do not define clear boundaries or specify that the agent should ignore instructions embedded within the fetched content.
- Capability inventory: The skill allows the agent to write several files to the local file system under the
scripts/marketing/directory. - Sanitization: There is no requirement for the agent to sanitize or escape the content retrieved from external sources before using it to generate marketing copy or strategy documents.
- [NO_CODE]: The skill consists entirely of markdown instructions and does not include any executable scripts, binaries, or configuration files that could run on the host system.
Audit Metadata