campaign-brief-generator

Pass

Audited by Gen Agent Trust Hub on Jul 10, 2026

Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
  • [PROMPT_INJECTION]: The skill has a potential vulnerability to indirect prompt injection due to its handling of external data.\n
  • Ingestion points: The skill collects campaign details (Goal, ICP, Product Context) from the user in Phase 0 of SKILL.md.\n
  • Boundary markers: No delimiters or safety instructions are used to separate the user-provided data from the agent's logic.\n
  • Capability inventory: The agent is instructed to write the final output to a file path within the clients/ directory.\n
  • Sanitization: No data validation or sanitization is performed on the user's input before it is used to generate the file content or construct the file path.\n- [NO_CODE]: This skill is composed entirely of natural language instructions and does not contain any scripts, executables, or dependency files.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 10, 2026, 03:06 PM
Security Audit — agent-trust-hub — campaign-brief-generator