editorial-ops

Pass

Audited by Gen Agent Trust Hub on Sep 24, 2026

Risk Level: SAFENO_CODE
Full Analysis
  • [NO_CODE]: The skill is comprised entirely of Markdown files including instructions, checklists, and templates (assets/distribution_brief.md, assets/editorial_calendar_template.md). No Python scripts, Node.js files, or other executable binaries are present.
  • [SAFE]: The content describes legitimate marketing and editorial processes, such as tracking content production, managing approvals, and planning distribution across channels like LinkedIn and Email. No patterns of prompt injection, data exfiltration, or obfuscation were detected.
  • [INDIRECT_PROMPT_INJECTION]: While the skill mentions fetching data from external sources like HubSpot and GA4 using the Context7 tool, it functions as a procedural guide for the agent. The ingestion of this external data represents a standard operational surface, and the instructions focus on defining measurement plans rather than processing untrusted input in a way that would trigger automated actions.
  • Ingestion points: External GA4 and HubSpot documentation fetched at runtime via Context7.
  • Boundary markers: None explicitly defined in the templates.
  • Capability inventory: Mentions patching CMS snippets (Serena), capturing screenshots (Playwright), and fetching documentation (Context7).
  • Sanitization: None described in the text instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 24, 2026, 12:49 AM
Security Audit — agent-trust-hub — editorial-ops