ecommerce-content-marketing
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill exhibits an indirect prompt injection attack surface by collecting and processing third-party data from various online platforms.
- Ingestion points: External data is fetched via
web_searchandweb_fetchwhen scanning Amazon reviews, Reddit threads, Trustpilot feedback, YouTube comments, TikTok comments, and competitor website pages as outlined in the Mode A and Mode B workflows withinSKILL.md. - Boundary markers: Absent. The instructions do not define distinct formatting boundaries or explicit instructions for the agent to treat the fetched content purely as data or to ignore text-based instructions contained within those reviews.
- Capability inventory: The available capabilities are restricted to information retrieval tools (
web_searchandweb_fetch). There are no capabilities for writing files, running system commands, or execution of arbitrary code. - Sanitization: Absent. The instructions do not prescribe any pre-processing, filtering, or escaping of the retrieved content prior to parsing it into the strategy templates.
Audit Metadata