public-relations

Pass

Audited by Gen Agent Trust Hub on Aug 28, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to process external information such as journalist research, media kits, and press requests. This represents a potential surface for indirect prompt injection where malicious instructions could be embedded in data processed by the agent. However, the skill includes an 'Operating contract' that mandates verifying information from primary sources and requiring explicit authorization before any external contact or publication, which significantly mitigates this risk.
  • [SAFE]: The skill's primary function is to provide structured guidance for PR strategy and production. It does not perform any automated tool calls, file writes, or network communications. It reads a local file .agents/marketing-context.md for business context, which is standard behavior for specialized agent skills.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 28, 2026, 11:55 AM
Security Audit — agent-trust-hub — public-relations