direct-response-copy
Pass
Audited by Gen Agent Trust Hub on Jul 14, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill instructions and reference files were analyzed for security risks. No evidence of prompt injection, data exfiltration, obfuscation, or malicious command execution was found. The skill operates within its defined scope of reading brand guidelines and writing marketing campaign materials.
- [PROMPT_INJECTION]: The skill possesses an indirect prompt injection surface as it ingests brand-specific configuration files (brand/*.md) and user-provided text for editing. However, this functionality is central to its purpose as a copywriting tool. The use of structured scoring rubrics and the Seven Sweeps editing framework provides a logical constraint on how external data is processed. 1. Ingestion points: Project files under the brand/ directory and user-supplied strings for copy improvement. 2. Boundary markers: No explicit delimiters are used to separate brand data from instructions, but the agent is guided by specific modes (Generate, Edit, Cold-Email) that limit the scope of processing. 3. Capability inventory: File system write access to the marketing/campaigns/ directory and brand/ assets. 4. Sanitization: The skill relies on standard agent behavior and structured evaluation rather than explicit content sanitization filters.
Audit Metadata