deepen-plan

Pass

Audited by Gen Agent Trust Hub on Jul 14, 2026

Risk Level: SAFE
Full Analysis
  • [DATA_EXPOSURE]: The skill reads from local files in the brand/ and marketing/ directories. This behavior is documented and necessary for its primary function of context-aware plan enhancement.
  • [EXTERNAL_DOWNLOADS]: Mentions the use of helper agents (mktg-audience-researcher, mktg-competitive-scanner). These are internal platform references used for delegated research tasks and do not represent untrusted external code.
  • [COMMAND_EXECUTION]: The skill performs file-write operations to update marketing plans and append learnings to brand/learnings.md, which is consistent with its stated purpose.
  • [PROMPT_INJECTION]: The skill processes untrusted user data (existing marketing plans) without explicit boundary markers or sanitization, creating a surface for indirect prompt injection. However, the risk is minimal given the specialized marketing context and lack of sensitive system capabilities.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 14, 2026, 02:05 PM
Security Audit — agent-trust-hub — deepen-plan