sms
Pass
Audited by Gen Agent Trust Hub on Jun 20, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: No malicious patterns or security risks were identified. The skill is entirely composed of markdown documentation and JSON evaluation files without executable code.
- [PROMPT_INJECTION]: No instructions were found that attempt to bypass AI safety guidelines or override system prompts. The content is focused on marketing strategy and compliance.
- [DATA_EXFILTRATION]: The skill does not perform any network requests or access sensitive local files like SSH keys or environment secrets. All referenced domains are well-known marketing services.
- [REMOTE_CODE_EXECUTION]: There are no scripts, command-line executions, or remote download patterns in the skill files. It does not attempt to install or run external software.
- [INDIRECT_PROMPT_INJECTION]: The skill includes instructions to read context from files like
.agents/product-marketing.mdto personalize responses. - Ingestion points:
.agents/product-marketing.md,.claude/product-marketing.md, andproduct-marketing-context.md(referenced in SKILL.md). - Boundary markers: Absent; the skill does not use specific delimiters to separate this context from its primary instructions.
- Capability inventory: None; there are no subprocess calls, file-write operations, or network tools available in the skill that could be exploited.
- Sanitization: Absent; the skill relies on the agent's default handling of text context.
- [OBFUSCATION]: No obfuscated text, encoded URLs, or hidden characters were detected during the analysis of the documentation or templates.
Audit Metadata