marketing-orchestrator

Pass

Audited by Gen Agent Trust Hub on Jul 31, 2026

Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it ingests untrusted data via web scraping and research capabilities. This external content is processed by the agent, which has access to powerful tools, potentially allowing malicious instructions embedded in scraped pages to influence agent actions.
  • Ingestion points: Untrusted data enters the system through the capabilities/web-research and capabilities/web-scraping modules as described in the workflow and capability handoff sections of SKILL.md.
  • Boundary markers: The instructions lack specific delimiters or directions for the agent to ignore or sanitize instructions found within external data.
  • Capability inventory: The agent has access to capabilities/file-operations, capabilities/browser-automation, and capabilities/github-repository, providing a significant impact surface if an injection occurs.
  • Sanitization: No sanitization or content validation steps are defined for external data.
  • [EXTERNAL_DOWNLOADS]: The skill implements a self-update workflow that uses the agent-update-manager to check a remote repository and install updates. While this process requires user approval, it involves the retrieval and execution of remote code.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 31, 2026, 02:04 PM
Security Audit — agent-trust-hub — marketing-orchestrator