lead-magnets
Pass
Audited by Gen Agent Trust Hub on May 5, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill package is composed exclusively of Markdown documentation and instructional text; no executable scripts, binaries, or automated tools are included.
- [SAFE]: There are no hardcoded credentials, API keys, or sensitive file paths targeted for exfiltration.
- [SAFE]: No network activity, external downloads, or remote code execution patterns were detected.
- [SAFE]: The skill mentions reading a local marketing context file (.agents/product-marketing-context.md) if it exists, which is a benign context-gathering behavior for a marketing-focused agent.
- [SAFE]: Indirect Prompt Injection Surface Analysis:
- Ingestion points: SKILL.md (reads local product-marketing-context.md).
- Boundary markers: Absent.
- Capability inventory: None (the skill defines no custom tools or execution scripts).
- Sanitization: Absent. Given the complete absence of capabilities or tool-access in this skill, the data ingestion point represents zero practical risk.
Audit Metadata