paw-mkt-agent-agency
Pass
Audited by Gen Agent Trust Hub on May 20, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill ingests data from user-defined files such as
brand-context.mdandstrategy.mdto generate specialist briefs. This creates an indirect prompt injection surface where malicious instructions embedded in these files could attempt to influence the agent's behavior. However, this risk is mitigated by the skill's core architecture, which mandates human-in-the-loop (HITL) approval before any brief is produced or any file is written to the workspace. - [SAFE]: The skill follows the principle of least privilege by acting only as a coordinator and explicitly forbidding itself from generating actual marketing content. It uses standard local directory structures for project management and does not exhibit any patterns of unauthorized data exfiltration, obfuscation, or remote code execution.
Audit Metadata