gtm-monetization

Pass

Audited by Gen Agent Trust Hub on Apr 1, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill is designed for business analysis and operates locally within the project directory to read and write configuration files.
  • [PROMPT_INJECTION]: The skill has a surface for indirect prompt injection as it ingests untrusted data from local files.
  • Ingestion points: Reads from data/gtm/icp_profiles.json, data/gtm/project_context.json, data/cfo/assumptions.json, and CLAUDE.md.
  • Boundary markers: No explicit markers or safety instructions are used when interpolating file contents.
  • Capability inventory: The skill can write output to data/gtm/pricing_strategy.json and data/gtm/revenue_parameters.json but has no network or shell execution capabilities.
  • Sanitization: No sanitization or validation of the ingested file content is performed.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 1, 2026, 12:08 AM
Security Audit — agent-trust-hub — gtm-monetization