xyq-marketing-skill

Pass

Audited by Gen Agent Trust Hub on Sep 25, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill requires the installation of the @pippit-dev/cli package from the NPM registry to provide the necessary command-line interface for interacting with the Marketing API. This is a vendor-provided tool required for the skill's primary function.
  • [COMMAND_EXECUTION]: The orchestration script scripts/marketing.js spawns the pippit-tool-cli binary as a subprocess to perform actions like uploading assets, submitting generation tasks, and checking account balances. The script uses secure spawning methods (shell: false) and communicates via JSON to prevent shell injection.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to process natural language instructions and user-provided media assets. It mitigates injection risks by instructing the agent to preserve original user instructions without unauthorized expansion and by using strict JSON serialization when passing data to the backend API.
  • [DATA_EXFILTRATION]: The script implements a 'Source Attribution' feature that reads specific environment variables (such as CLAUDECODE or CURSOR_AGENT) to identify the host platform. This identifier is sent to the vendor's API for usage statistics. The skill documentation explicitly restricts this information to stable platform identifiers, excluding sensitive data like session IDs or user prompts.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 25, 2026, 03:32 PM