marketing-context
Pass
Audited by Gen Agent Trust Hub on Sep 4, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection as it instructs the agent to ingest and analyze untrusted content from the codebase to generate its output.
- Ingestion points: The agent is instructed to "Study the repo — README, landing pages, marketing copy, about pages, package.json, existing docs" (SKILL.md).
- Boundary markers: There are no explicit boundary markers or instructions to disregard potential commands embedded within the analyzed repository files.
- Capability inventory: The agent can write the summarized findings to a persistent file located at
.agents/marketing-context.md(SKILL.md). - Sanitization: The skill lacks validation or sanitization mechanisms to filter malicious instructions contained within the ingested project files.
Audit Metadata