personalization-logic
Pass
Audited by Gen Agent Trust Hub on Sep 24, 2026
Risk Level: SAFENO_CODEINDIRECT_PROMPT_INJECTION
Full Analysis
- [NO_CODE]: The skill consists entirely of documentation, frameworks, and templates for marketing personalization. It does not contain any executable scripts, tools, or command-line instructions.
- [INDIRECT_PROMPT_INJECTION]: The skill framework involves processing external data such as persona, industry, and product usage via personalization tokens, which creates a theoretical ingestion surface.
- Ingestion points: 'Segmentation Inputs' (SKILL.md).
- Boundary markers: The documentation does not specify delimiters or instructions to ignore potentially malicious embedded content within tokens.
- Capability inventory: None. The skill does not have any code or perform any file, network, or system operations.
- Sanitization: No data validation or sanitization steps are mentioned in the governance or QA sections.
Audit Metadata