companify-cmo

Pass

Audited by Gen Agent Trust Hub on Aug 19, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: No prompt injection attempts were found. The instructions are clearly focused on the defined task of marketing strategy generation without attempting to override system constraints or safety filters.
  • [DATA_EXPOSURE]: No hardcoded credentials, API keys, or exposure of sensitive system files were detected. The skill interacts exclusively with project-specific documentation files (e.g., brand/strategy.md).
  • [REMOTE_CODE_EXECUTION]: There are no patterns indicating the download or execution of remote code or scripts.
  • [COMMAND_EXECUTION]: No unauthorized or dangerous shell command execution was found. The operations are limited to reading and writing markdown files within the local environment.
  • [OBFUSCATION]: No obfuscated content, such as Base64, zero-width characters, or homoglyphs, was detected in the skill files.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes data from external files (e.g., brand strategy documents), which represents a potential injection surface. However, since the skill does not possess high-privilege capabilities like network access or shell execution, the risk is negligible.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 19, 2026, 10:25 PM
Security Audit — agent-trust-hub — companify-cmo