advertising-kickoff
Pass
Audited by Gen Agent Trust Hub on Sep 13, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to automatically ingest untrusted data from the execution environment to bypass the interview process, creating a vulnerability surface where instructions in project files could influence agent behavior.\n
- Ingestion points: The skill instructions in
SKILL.md(§ 1) direct the agent to read the repository's git history, inventory existing files (README, briefs, campaign docs, and media plans), and detect available integrations (CRM, analytics sources, and ad-account exports).\n - Boundary markers: No specific delimiters or "ignore embedded instructions" warnings are defined for the data read from the project environment.\n
- Capability inventory: The skill acts as a router for the 31-skill
mbfinotti/advertising-skillscollection, maintains a local project context artifact (advertising-context.md), and manages persistent agent memory.\n - Sanitization: The instructions do not include requirements for validating, escaping, or filtering content from the ingested files before processing.
Audit Metadata