funnel-audit

Pass

Audited by Gen Agent Trust Hub on May 8, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: The skill processes external data via a URL argument and local brand files, which introduces an indirect prompt injection surface.
  • Ingestion points: SKILL.md (via argument hint) and files in ~/.claude-marketing/brands/.
  • Boundary markers: Absent. The skill does not define specific delimiters for external content.
  • Capability inventory: None. The skill does not possess tools for network exfiltration, arbitrary command execution, or file writing.
  • Sanitization: Absent. No explicit validation of the ingested data is described.
Audit Metadata
Risk Level
SAFE
Analyzed
May 8, 2026, 11:40 PM