paw-mkt-agent-agency

Pass

Audited by Gen Agent Trust Hub on May 20, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill ingests data from user-defined files such as brand-context.md and strategy.md to generate specialist briefs. This creates an indirect prompt injection surface where malicious instructions embedded in these files could attempt to influence the agent's behavior. However, this risk is mitigated by the skill's core architecture, which mandates human-in-the-loop (HITL) approval before any brief is produced or any file is written to the workspace.
  • [SAFE]: The skill follows the principle of least privilege by acting only as a coordinator and explicitly forbidding itself from generating actual marketing content. It uses standard local directory structures for project management and does not exhibit any patterns of unauthorized data exfiltration, obfuscation, or remote code execution.
Audit Metadata
Risk Level
SAFE
Analyzed
May 20, 2026, 10:37 AM
Security Audit — agent-trust-hub — paw-mkt-agent-agency