specialist-marketing-livestream-commerce-coach

Pass

Audited by Gen Agent Trust Hub on Aug 15, 2026

Risk Level: SAFENO_CODEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill contains a vulnerability surface for indirect prompt injection.\n
  • Ingestion points: The {the user's question} variable is interpolated directly into the sub-agent prompt within SKILL.md.\n
  • Boundary markers: Absent; there are no clear delimiters or instructions for the model to treat the interpolated text as untrusted data.\n
  • Capability inventory: The skill is limited to spawning a sub-agent with marketing expertise; no specific tools or system-level capabilities are requested in the frontmatter.\n
  • Sanitization: No sanitization, escaping, or validation of the user-provided input is performed before interpolation.\n- [NO_CODE]: The skill consists exclusively of markdown instructions and YAML metadata. It does not include any scripts, executable files, or direct shell command patterns.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 15, 2026, 08:50 PM
Security Audit — agent-trust-hub — specialist-marketing-livestream-commerce-coach