cmo
Pass
Audited by Gen Agent Trust Hub on Jun 14, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill operates as a legitimate marketing strategy tool within the local project environment.
- [DATA_EXFILTRATION]: No network-facing operations, external URLs, or data exfiltration patterns were identified.
- [COMMAND_EXECUTION]: The skill does not contain instructions for shell command execution, subprocess spawning, or dynamic code evaluation.
- [PROMPT_INJECTION]: The skill utilizes an attack surface for indirect prompt injection by reading external context files (data/gtm/project_context.json, data/cfo/latest_forecast.json, data/product/roadmap.json, and CLAUDE.md). However, because the skill possesses no high-privilege capabilities such as network communication or administrative file access, this surface cannot be meaningfully exploited. Ingestion points: data/gtm/project_context.json, data/cfo/latest_forecast.json, data/product/roadmap.json, CLAUDE.md. Boundary markers: Absent. Capability inventory: Local file read/write within project data directories. Sanitization: Absent.
Audit Metadata