gtm-icp
Pass
Audited by Gen Agent Trust Hub on Jun 14, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: No security issues detected. The skill is designed for B2B strategy and positioning. It utilizes local project files for state persistence and context, which is standard behavior for development-focused AI skills.
- [PROMPT_INJECTION]: The skill utilizes the
$ARGUMENTSvariable at the beginning of the persona prompt. This represents a controlled ingestion of user input into the system instructions for the purpose of identifying the project name, which does not pose a security risk in this context. - [COMMAND_EXECUTION]: The skill instructions describe writing structured JSON data to the local file system in the
data/gtm/directory. These file operations are strictly scoped to the project's data directory and align with the skill's functional requirements for persisting ICP profiles and messaging frameworks.
Audit Metadata