product-marketing-context

Pass

Audited by Gen Agent Trust Hub on Apr 14, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill's 'Auto-draft' workflow instructs the agent to analyze the repository codebase—including READMEs, landing pages, marketing copy, and package.json—to generate a context document. This surface is vulnerable to indirect prompt injection, as malicious instructions placed in these files by an attacker could be followed by the agent or poison the resulting marketing context.
  • [INDIRECT_PROMPT_INJECTION_EVIDENCE]:
  • Ingestion points: README.md, landing pages, marketing copy, and package.json.
  • Boundary markers: Absent; instructions do not specify using delimiters or ignoring instructions within the analyzed files.
  • Capability inventory: File system read access for analysis and write access to .agents/product-marketing-context.md.
  • Sanitization: Absent; the skill does not implement validation or filtering of the content extracted from project files before processing.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 14, 2026, 12:24 AM
Security Audit — agent-trust-hub — product-marketing-context