marketing-plan

Pass

Audited by Gen Agent Trust Hub on Aug 2, 2026

Risk Level: SAFEPROMPT_INJECTIONDATA_EXFILTRATIONCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The skill possesses an attack surface for indirect prompt injection. It instructs the agent to process content from a variety of external, potentially untrusted sources, including client-provided materials in the materials/ folder and live data from Stripe, GA4, and GitHub. There are no boundary markers or instructions to treat this content as data rather than instructions.
  • Ingestion points: Files placed in ~/marketing-plans/{client-slug}/materials/ and outputs from connected MCPs (Stripe, Ahrefs, GitHub, etc.).
  • Boundary markers: Absent; no delimiters or "ignore embedded instructions" warnings are used when interpolating external data.
  • Capability inventory: File system access (~/marketing-plans/), Git operations (gh CLI for cloning and pushing), and browser automation tools (agent-browser).
  • Sanitization: Absent; no escaping or validation of external input is mentioned.
  • [DATA_EXFILTRATION]: The skill has access to sensitive business and financial data via the Stripe MCP (including MRR, ARR, and churn metrics). It also includes the capability to publish plans to external GitHub repositories. This combination provides a potential path for data exfiltration if the agent is manipulated by malicious instructions embedded in the client materials it processes.
  • [COMMAND_EXECUTION]: The skill's operations involve the use of powerful command-line and browser automation tools. Specifically, it uses the GitHub CLI to clone, commit, and push content to remote repositories and uses browser tools for web-based research. These capabilities could be leveraged for unauthorized actions if the agent's logic is compromised via indirect injection.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 2, 2026, 03:58 PM
Security Audit — agent-trust-hub — marketing-plan