specialist-marketing-app-store-optimizer
Pass
Audited by Gen Agent Trust Hub on Aug 15, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill's structure incorporates user input directly into the prompt of an ephemeral sub-agent, which is a standard but documented surface for indirect instruction injection. \n
- Ingestion points: The user input is interpolated via the
{the user's question}placeholder in the Agent tool call withinSKILL.md. \n - Boundary markers: No explicit markers or delimiters are present to isolate the user's input from the sub-agent's primary instructions. \n
- Capability inventory: The skill utilizes the
Agenttool to spawn a specialized sub-agent context. \n - Sanitization: User input is passed directly to the sub-agent without escaping or validation.
Audit Metadata