marketing-analytics

Pass

Audited by Gen Agent Trust Hub on Jun 24, 2026

Risk Level: SAFENO_CODE
Full Analysis
  • [SAFE]: The skill consists entirely of Markdown files defining persona behaviors and reporting templates. No executable code (Python, JavaScript, or shell scripts) is included in the package.\n- [NO_CODE]: The absence of logic or scripts eliminates risks related to command execution, privilege escalation, or persistence mechanisms.\n- [PROMPT_INJECTION]: The skill instructs the agent to ingest a local context file (.agents/marketing-context.md). While this represents a surface for indirect prompt injection, the risk is negligible as the skill lacks high-privilege capabilities or external network tools. Evidence chain: 1. Ingestion: .agents/marketing-context.md (referenced in SKILL.md). 2. Boundary markers: Absent. 3. Capability inventory: None (Instructional documentation only). 4. Sanitization: Absent.\n- [DATA_EXFILTRATION]: No network operation patterns or data exfiltration vectors were detected in the instructions or metadata.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 24, 2026, 06:02 PM
Security Audit — agent-trust-hub — marketing-analytics