utm-builder
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to process untrusted data provided by the user (URLs, campaign names, and channel details) to create structured tracking links.
- Ingestion points: User inputs for the target URL, campaign name, source, medium, and content variants.
- Boundary markers: The instructions lack explicit delimiters or instructions for the agent to ignore potentially malicious content embedded within user-provided campaign metadata or URLs.
- Capability inventory: The skill reads local workspace files for context (
strategy/brand.md,about/me.md,content/ideas.md) and writes artifacts to the local filesystem (content/<platform>/drafts/). - Sanitization: There is no explicit validation or sanitization of input strings beyond recommending lowercase formatting for UTM parameters.
Audit Metadata