skills/phuryn/pm-skills/gtm-motions/Gen Agent Trust Hub

gtm-motions

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFENO_CODE
Full Analysis
  • [SAFE]: The skill consists entirely of Markdown text providing a strategic framework. It does not include any scripts, binaries, or executable commands.
  • [SAFE]: No data exfiltration or credential harvesting patterns were detected. While the skill mentions various third-party marketing tools (e.g., HubSpot, Stripe, Google Ads), these are listed as categorical examples for the user's reference and are not invoked by the skill.
  • [SAFE]: External links point to informational articles on a product management blog (productcompass.pm). No remote code execution or automated downloads are associated with these links.
  • [INDIRECT_PROMPT_INJECTION]: The skill accepts external data via $ARGUMENTS.
  • Ingestion points: User-provided product descriptions and market data in SKILL.md.
  • Boundary markers: None explicitly defined in the instructions.
  • Capability inventory: None; the skill has no file-write, network, or subprocess execution capabilities.
  • Sanitization: None; however, because the skill lacks executable capabilities, the risk surface is effectively null.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 12:02 PM
Security Audit — agent-trust-hub — gtm-motions