product-marketing

Pass

Audited by Gen Agent Trust Hub on Aug 2, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The 'Auto-draft from codebase' feature introduces an attack surface for indirect prompt injection by processing untrusted repository content.\n
  • Ingestion points: The skill is instructed to read the README, landing pages, marketing copy, package.json, and any existing documentation within the codebase to draft the context document (SKILL.md).\n
  • Boundary markers: The skill instructions do not specify any delimiters or explicit boundary markers to help the agent distinguish between informational content and embedded instructions in the ingested files.\n
  • Capability inventory: The skill has the capability to perform repository-wide file reads and write the resulting output to a configuration file at .agents/product-marketing.md (SKILL.md).\n
  • Sanitization: There is no requirement or logic provided to sanitize, validate, or filter content extracted from the codebase before it is used to generate the marketing context draft.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 2, 2026, 03:58 PM
Security Audit — agent-trust-hub — product-marketing