paywalls
Pass
Audited by Gen Agent Trust Hub on Aug 26, 2026
Risk Level: SAFE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill instructions include a directive to read local context files such as
.agents/product-marketing.mdor.claude/product-marketing.mdto inform its recommendations. This creates a surface where instructions embedded in those files could influence the agent's advice. However, because the skill has no access to dangerous tools (like network access or file writing), the security risk is negligible. - Ingestion points:
SKILL.md(via instructions to readproduct-marketing.mdvariations). - Boundary markers: Absent; the skill does not specify delimiters for the context file content.
- Capability inventory: The skill is purely informational and lacks any executable capabilities or destructive tools.
- Sanitization: Absent; content from the context files is used directly for reasoning.
Audit Metadata