funnel-audit
Pass
Audited by Gen Agent Trust Hub on May 8, 2026
Risk Level: SAFE
Full Analysis
- [PROMPT_INJECTION]: The skill processes external data via a URL argument and local brand files, which introduces an indirect prompt injection surface.
- Ingestion points:
SKILL.md(via argument hint) and files in~/.claude-marketing/brands/. - Boundary markers: Absent. The skill does not define specific delimiters for external content.
- Capability inventory: None. The skill does not possess tools for network exfiltration, arbitrary command execution, or file writing.
- Sanitization: Absent. No explicit validation of the ingested data is described.
Audit Metadata