lead-magnets

Pass

Audited by Gen Agent Trust Hub on May 5, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill package is composed exclusively of Markdown documentation and instructional text; no executable scripts, binaries, or automated tools are included.
  • [SAFE]: There are no hardcoded credentials, API keys, or sensitive file paths targeted for exfiltration.
  • [SAFE]: No network activity, external downloads, or remote code execution patterns were detected.
  • [SAFE]: The skill mentions reading a local marketing context file (.agents/product-marketing-context.md) if it exists, which is a benign context-gathering behavior for a marketing-focused agent.
  • [SAFE]: Indirect Prompt Injection Surface Analysis:
  • Ingestion points: SKILL.md (reads local product-marketing-context.md).
  • Boundary markers: Absent.
  • Capability inventory: None (the skill defines no custom tools or execution scripts).
  • Sanitization: Absent. Given the complete absence of capabilities or tool-access in this skill, the data ingestion point represents zero practical risk.
Audit Metadata
Risk Level
SAFE
Analyzed
May 5, 2026, 10:42 AM
Security Audit — agent-trust-hub — lead-magnets