marketing-automation
Pass
Audited by Gen Agent Trust Hub on Aug 28, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes potentially untrusted data in the form of marketing task descriptions which serves as an ingestion point for indirect prompt injection.
- Ingestion points: The skill ingests user-supplied definitions of marketing tasks and optionally reads from a local
.agents/marketing-context.mdfile (SKILL.md). - Boundary markers: The instructions do not define specific delimiters or boundary markers to separate user-provided task content from the agent's system instructions.
- Capability inventory: The skill is explicitly designed to handle mutation capabilities including sending messages, publishing content, and modifying marketing campaigns (SKILL.md).
- Sanitization: There are no instructions for sanitizing, escaping, or validating the content of the tasks before the agent processes or acts upon them.
Audit Metadata