07-marketing-report-global
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill provides a surface for ingesting untrusted data provided by the user (such as marketing metrics, ad names, and channel descriptions).
- Ingestion points: The 'Information gathering' section in SKILL.md prompts the user for ad spend, revenue, and campaign details.
- Boundary markers: The output templates do not utilize specific delimiters or instructions to distinguish between data and potential instructions.
- Capability inventory: No dangerous capabilities (such as shell command execution, network requests, or file system modifications) are present in the skill.
- Sanitization: No data sanitization or validation logic is defined in the instructions.
- [SAFE]: The skill consists entirely of markdown templates and instructional content. Analysis confirmed no presence of obfuscation, remote code execution, privilege escalation, or persistence mechanisms.
Audit Metadata