build-in-public
Pass
Audited by Gen Agent Trust Hub on Jun 21, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill consists of markdown instructions and templates intended for marketing strategy. It does not contain any executable code, scripts, or commands that interact with the system or network in a malicious way.
- [DATA_EXPOSURE]: The skill's primary purpose is to guide the user in sharing business progress. While it suggests sharing revenue figures, it includes explicit safety warnings under the 'Don'ts' section to avoid sharing sensitive data or intellectual property.
- [INDIRECT_PROMPT_INJECTION]: The automation section suggests triggering social media posts from external sources such as GitHub commits or Stripe events. This presents a potential surface for indirect prompt injection where malicious input in a commit message could affect the generated post, but this is a common characteristic of such automation workflows and is not a direct flaw of the skill code itself.
Audit Metadata