funnel-architect

Pass

Audited by Gen Agent Trust Hub on May 14, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructions in SKILL.md call a local Python script campaign-tracker.py to retrieve campaign history. This is part of the functional integration with the user's local marketing environment.
  • [PROMPT_INJECTION]: The skill ingests marketing guidelines and brand profiles from files in the ~/.claude-marketing/ directory to configure its output. This ingestion is a core feature of the skill's brand-aware design and is used to enforce compliance and voice settings.
  • Ingestion points: Files located in ~/.claude-marketing/brands/{slug}/ and skills/context-engine/ (referenced in SKILL.md).
  • Boundary markers: None explicitly defined for file ingestion.
  • Capability inventory: Execution of campaign-tracker.py (referenced in SKILL.md).
  • Sanitization: None explicitly defined.
Audit Metadata
Risk Level
SAFE
Analyzed
May 14, 2026, 04:17 AM
Security Audit — agent-trust-hub — funnel-architect