content-strategy
Pass
Audited by Gen Agent Trust Hub on May 5, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: No malicious instructions, obfuscation, or unauthorized network operations were identified.- [DATA_EXPOSURE]: The skill reads from business context files (e.g., .agents/product-marketing-context.md) to personalize its strategy. This is a standard practice for providing the agent with necessary background information within its secure environment.- [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to ingest and analyze untrusted data from customer call transcripts, survey responses, and web search results from platforms like Reddit and Quora. Evidence: 1. Ingestion points: .agents/product-marketing-context.md, call transcripts, surveys, and web search results. 2. Boundary markers: Absent. 3. Capability inventory: Web search. 4. Sanitization: Absent. While this represents an attack surface for indirect prompt injection, the skill is focused on strategy planning and data extraction rather than executing commands based on the input.
Audit Metadata