content-strategy

Pass

Audited by Gen Agent Trust Hub on Jul 10, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection attack surface because it ingests untrusted data from external financial connectors to generate recommendations.
  • Ingestion points: Data including product names, service categories, and transaction history is pulled via the profit-loss-quickbooks-account, list_transactions, and Square API connectors.
  • Boundary markers: The instructions do not define specific delimiters or security warnings to prevent the model from following instructions that might be embedded within product names or descriptions retrieved from the financial systems.
  • Capability inventory: The skill processes this data to create strategic briefs and structured JSON data intended for use by downstream tools such as canva-creator.
  • Sanitization: There is no evidence of string validation or sanitization for the content retrieved from external APIs before it is incorporated into the agent's context.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 10, 2026, 12:22 PM
Security Audit — agent-trust-hub — content-strategy