companify-cmo
Pass
Audited by Gen Agent Trust Hub on Aug 19, 2026
Risk Level: SAFE
Full Analysis
- [PROMPT_INJECTION]: No prompt injection attempts were found. The instructions are clearly focused on the defined task of marketing strategy generation without attempting to override system constraints or safety filters.
- [DATA_EXPOSURE]: No hardcoded credentials, API keys, or exposure of sensitive system files were detected. The skill interacts exclusively with project-specific documentation files (e.g., brand/strategy.md).
- [REMOTE_CODE_EXECUTION]: There are no patterns indicating the download or execution of remote code or scripts.
- [COMMAND_EXECUTION]: No unauthorized or dangerous shell command execution was found. The operations are limited to reading and writing markdown files within the local environment.
- [OBFUSCATION]: No obfuscated content, such as Base64, zero-width characters, or homoglyphs, was detected in the skill files.
- [INDIRECT_PROMPT_INJECTION]: The skill processes data from external files (e.g., brand strategy documents), which represents a potential injection surface. However, since the skill does not possess high-privilege capabilities like network access or shell execution, the risk is negligible.
Audit Metadata