launch-strategy

Pass

Audited by Gen Agent Trust Hub on Jul 14, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill performs legitimate marketing planning tasks, reading from the brand/ directory and writing to marketing/launch/. These actions are well-defined and restricted to the project's workspace.\n- [PROMPT_INJECTION]: The skill possesses an indirect prompt injection surface because it processes untrusted data from the local brand/ directory to generate its output.\n
  • Ingestion points: Files brand/voice-profile.md, brand/positioning.md, and brand/audience.md are read to provide context for the launch plan.\n
  • Boundary markers: None are present; the instructions do not include specific delimiters or warnings to ignore potentially malicious content within the brand files.\n
  • Capability inventory: The skill's capabilities are restricted to generating and writing text files (marketing/launch/plan.md, marketing/launch/checklist.md). It lacks access to subprocess execution, network requests, or sensitive system files.\n
  • Sanitization: No sanitization or validation is applied to the data ingested from the brand files.\n- [SAFE]: No instances of remote code execution, hardcoded credentials, persistence mechanisms, or obfuscated content were detected in the skill's instructions or reference files.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 14, 2026, 02:06 PM
Security Audit — agent-trust-hub — launch-strategy