cmo-advisor

Pass

Audited by Gen Agent Trust Hub on Apr 18, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill is focused on marketing leadership tasks and shows no evidence of malicious intent, credential exfiltration, or obfuscation.
  • [COMMAND_EXECUTION]: The skill facilitates budget and growth modeling by executing local Python scripts (marketing_budget_modeler.py, growth_model_simulator.py). These scripts are described as internal tools for the skill's primary function and do not involve remote downloads.
  • [PROMPT_INJECTION]: The skill reads from company-context.md (Ingestion Point), creating a surface for indirect prompt injection. However, its capabilities are confined to its provided modeling scripts (Capability Inventory: marketing_budget_modeler.py, growth_model_simulator.py). There are no specific boundary markers or sanitization routines mentioned in the instructions (Boundary Markers: Absent; Sanitization: Absent).
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 18, 2026, 12:07 PM
Security Audit — agent-trust-hub — cmo-advisor