plan-gtm
Fail
Audited by Gen Agent Trust Hub on Sep 22, 2026
Risk Level: CRITICALEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill's reference file
references/benchmarks-2026.mdcontains links to external domains that have been flagged as malicious or phishing by security scanners. Specifically,saasmag.comis identified as blacklisted, andgetmonetizely.comis flagged as a phishing site. These links are provided as authoritative sources for GTM strategy benchmarks, posing a risk to users or agents that navigate to them. - [INDIRECT_PROMPT_INJECTION]: The skill performs an inventory of untrusted repository files, creating a vulnerability surface where maliciously crafted repo content could influence agent behavior.
- Ingestion points: README, LICENSE, and source code files analyzed during the Step A inventory in
SKILL.md. - Boundary markers: Absent; there are no delimiters or instructions to treat repository content as data distinct from instructions.
- Capability inventory: The skill performs repository-wide grepping and file reads, and writes output to
plan-gtm.md. - Sanitization: Absent; no filtering or validation is performed on the ingested repository content before it is used to formulate recommendations.
Recommendations
- AI detected serious security threats
- Contains 4 malicious URL(s) - DO NOT USE
Audit Metadata