offers

Pass

Audited by Gen Agent Trust Hub on Jun 20, 2026

Risk Level: SAFENO_CODE
Full Analysis
  • [SAFE]: The skill is entirely composed of informational markdown files and does not contain any executable scripts, binaries, or dynamic code execution patterns.
  • [NO_CODE]: No source code (Python, JavaScript, etc.) or configuration files for automated tools are present in the skill package.
  • [PROMPT_INJECTION]: The skill identifies potential ingestion points for untrusted data by instructing the agent to read marketing context from files like .agents/product-marketing.md. However, since the skill defines no dangerous capabilities, the risk associated with this surface is negligible.
  • Ingestion points: .agents/product-marketing.md, .claude/product-marketing.md, and product-marketing-context.md (as mentioned in SKILL.md).
  • Boundary markers: No specific delimiters or safety instructions are provided for these context files.
  • Capability inventory: No tool use, subprocess execution, or write permissions are requested or utilized by the skill.
  • Sanitization: No sanitization or validation logic is present for the ingested context data.
  • [SAFE]: No hardcoded credentials, sensitive file access (e.g., SSH keys, AWS configs), or exfiltration patterns were detected in any of the reference documents.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 20, 2026, 05:32 AM
Security Audit — agent-trust-hub — offers