marketing-plan
Pass
Audited by Gen Agent Trust Hub on Jun 20, 2026
Risk Level: SAFE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to process external materials such as pitch decks, research documents, and live API data from services like Stripe, GitHub, and Notion. This ingestion of untrusted external content represents a surface for indirect prompt injection, where an attacker could embed malicious instructions in those documents. However, this is an inherent risk of the skill's primary function and not a malicious design.
- [COMMAND_EXECUTION]: The skill instructions involve the use of various Model Context Protocol (MCP) tools and CLI utilities (e.g., Ahrefs, Typefully, GitHub) to perform research and document management. These operations are explicitly described as part of the fractional CMO workflow and are consistent with the skill's stated purpose.
Audit Metadata