gtm-motions
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFENO_CODE
Full Analysis
- [SAFE]: The skill consists entirely of Markdown text providing a strategic framework. It does not include any scripts, binaries, or executable commands.
- [SAFE]: No data exfiltration or credential harvesting patterns were detected. While the skill mentions various third-party marketing tools (e.g., HubSpot, Stripe, Google Ads), these are listed as categorical examples for the user's reference and are not invoked by the skill.
- [SAFE]: External links point to informational articles on a product management blog (productcompass.pm). No remote code execution or automated downloads are associated with these links.
- [INDIRECT_PROMPT_INJECTION]: The skill accepts external data via $ARGUMENTS.
- Ingestion points: User-provided product descriptions and market data in SKILL.md.
- Boundary markers: None explicitly defined in the instructions.
- Capability inventory: None; the skill has no file-write, network, or subprocess execution capabilities.
- Sanitization: None; however, because the skill lacks executable capabilities, the risk surface is effectively null.
Audit Metadata