positioning-messaging

Pass

Audited by Gen Agent Trust Hub on Jul 16, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [PROMPT_INJECTION]: The skill is designed to ingest and process data from untrusted external sources, including G2 reviews, Reddit threads, and competitor websites (Phase 2), as well as sensitive internal customer transcripts (Phase 1). It lacks explicit instructions for the agent to utilize boundary markers or to ignore potentially malicious instructions embedded within this external data. Capability inventory: The skill utilizes a local Python script (check-output.py) for output validation. Sanitization: No sanitization or filtering of external content is mentioned. This represents a surface for indirect prompt injection where data could influence downstream agent actions.
  • [COMMAND_EXECUTION]: The skill includes a local validation script, scripts/check-output.py, which is executed to verify that the generated positioning deliverables meet minimum length requirements and include necessary keywords. This script operates solely on local file content.
  • [EXTERNAL_DOWNLOADS]: The instructions refer to the optional use of 'LeadMagic Company Search and Technographics APIs' for enriching competitive data. These are vendor-owned resources provided by the skill's author for legitimate research tasks within the skill's defined scope.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 16, 2026, 03:21 PM
Security Audit — agent-trust-hub — positioning-messaging