ecommerce-content-marketing

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill exhibits an indirect prompt injection attack surface by collecting and processing third-party data from various online platforms.
  • Ingestion points: External data is fetched via web_search and web_fetch when scanning Amazon reviews, Reddit threads, Trustpilot feedback, YouTube comments, TikTok comments, and competitor website pages as outlined in the Mode A and Mode B workflows within SKILL.md.
  • Boundary markers: Absent. The instructions do not define distinct formatting boundaries or explicit instructions for the agent to treat the fetched content purely as data or to ignore text-based instructions contained within those reviews.
  • Capability inventory: The available capabilities are restricted to information retrieval tools (web_search and web_fetch). There are no capabilities for writing files, running system commands, or execution of arbitrary code.
  • Sanitization: Absent. The instructions do not prescribe any pre-processing, filtering, or escaping of the retrieved content prior to parsing it into the strategy templates.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 10:52 AM
Security Audit — agent-trust-hub — ecommerce-content-marketing