data-export
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes marketing data from external sources which could contain malicious instructions.
- Ingestion points: Data is retrieved from connected MCPs (Google Analytics, CRM, ad platforms) and local brand data files in ~/.claude-marketing/.
- Boundary markers: The skill does not implement specific delimiters or instructions to ignore embedded commands within the ingested data fields.
- Capability inventory: The agent can execute local Python scripts and perform network operations via database/spreadsheet MCPs.
- Sanitization: The skill performs PII redaction and schema normalization, but does not sanitize content specifically against prompt injection payloads.
- [COMMAND_EXECUTION]: The skill executes local Python utility scripts to manage internal state.
- Evidence: Invokes approval-manager.py, campaign-tracker.py, and execution-tracker.py from the plugin's script directory to handle approvals and data retrieval.
Audit Metadata