marketing-research-posting-plan

Pass

Audited by Gen Agent Trust Hub on Apr 18, 2026

Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
  • [PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection due to its core requirement to ingest untrusted web data.
  • Ingestion points: The workflow mandates browsing Reddit, forums, and GitHub discussions, which are attacker-controllable sources.
  • Boundary markers: The instructions do not define clear boundaries or specify that the agent should ignore instructions embedded within the fetched content.
  • Capability inventory: The skill allows the agent to write several files to the local file system under the scripts/marketing/ directory.
  • Sanitization: There is no requirement for the agent to sanitize or escape the content retrieved from external sources before using it to generate marketing copy or strategy documents.
  • [NO_CODE]: The skill consists entirely of markdown instructions and does not include any executable scripts, binaries, or configuration files that could run on the host system.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 18, 2026, 12:08 PM
Security Audit — agent-trust-hub — marketing-research-posting-plan