absolute-marketing

Pass

Audited by Gen Agent Trust Hub on Aug 10, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is entirely instructional and provides strategic marketing frameworks. It instructs the agent to read standard project files (such as README.md and package.json) to generate a marketing context document, which is a legitimate functional requirement for providing tailored advice.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from the repository to build a marketing profile, which represents a theoretical attack surface for indirect prompt injection.
  • Ingestion points: Documentation and metadata files within the project repository (SKILL.md).
  • Boundary markers: Absent; the instructions do not include specific delimiters or warnings for the agent to ignore instructions embedded within the scanned content.
  • Capability inventory: The agent uses file-reading tools to generate context; the skill does not include instructions for subprocess execution, shell commands, or network exfiltration based on the ingested data.
  • Sanitization: Absent.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 10, 2026, 02:05 PM
Security Audit — agent-trust-hub — absolute-marketing