marketing-demand-acquisition

Pass

Audited by Gen Agent Trust Hub on Sep 4, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: No evidence of instructions designed to bypass safety filters or override agent constraints was detected.
  • [DATA_EXFILTRATION]: No sensitive file paths, hardcoded credentials, or network exfiltration patterns were found. The skill uses standard UTM templates and HubSpot integration guidelines which are consistent with legitimate marketing operations.
  • [REMOTE_CODE_EXECUTION]: The included script scripts/calculate_cac.py is a simple calculator that uses standard library components to perform arithmetic. It does not contain any remote code download or execution patterns.
  • [OBFUSCATION]: All instructions and code are written in plain text. No Base64, zero-width characters, or hidden Unicode tags were identified.
  • [INDIRECT_PROMPT_INJECTION]: The skill documents workflows for handling lead data from external sources like HubSpot. However, the provided tools do not include risky capability surfaces (like command execution or file writing) that could be exploited by maliciously crafted data.
  • [DYNAMIC_CONTEXT_INJECTION]: The skill does not utilize the dynamic command execution syntax in its markdown files.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 4, 2026, 02:33 PM
Security Audit — agent-trust-hub — marketing-demand-acquisition