launch-ad-campaign
Pass
Audited by Gen Agent Trust Hub on May 9, 2026
Risk Level: SAFECOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes local helper scripts (approval-manager.py and execution-tracker.py) to process campaign approvals and maintain an audit log of launch activities.
- [DATA_EXFILTRATION]: The skill reads brand-specific profile data and guidelines from the ~/.claude-marketing/ directory to ensure campaign compliance and proper targeting.
- [PROMPT_INJECTION]: The skill processes untrusted brand configuration data, which serves as a potential surface for indirect prompt injection. Mandatory Evidence Chain: 1. Ingestion points: ~/.claude-marketing/brands/{slug}/profile.json and ~/.claude-marketing/brands/{slug}/guidelines/_manifest.json. 2. Boundary markers: None specified. 3. Capability inventory: Execution of local scripts and ad platform API operations. 4. Sanitization: None specified.
Audit Metadata