launch-strategy
Pass
Audited by Gen Agent Trust Hub on Jul 14, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [SAFE]: The skill performs legitimate marketing planning tasks, reading from the
brand/directory and writing tomarketing/launch/. These actions are well-defined and restricted to the project's workspace.\n- [PROMPT_INJECTION]: The skill possesses an indirect prompt injection surface because it processes untrusted data from the localbrand/directory to generate its output.\n - Ingestion points: Files
brand/voice-profile.md,brand/positioning.md, andbrand/audience.mdare read to provide context for the launch plan.\n - Boundary markers: None are present; the instructions do not include specific delimiters or warnings to ignore potentially malicious content within the brand files.\n
- Capability inventory: The skill's capabilities are restricted to generating and writing text files (
marketing/launch/plan.md,marketing/launch/checklist.md). It lacks access to subprocess execution, network requests, or sensitive system files.\n - Sanitization: No sanitization or validation is applied to the data ingested from the brand files.\n- [SAFE]: No instances of remote code execution, hardcoded credentials, persistence mechanisms, or obfuscated content were detected in the skill's instructions or reference files.
Audit Metadata