pricing-strategist
Pass
Audited by Gen Agent Trust Hub on Apr 22, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADS
Full Analysis
- [SAFE]: No security threats or malicious patterns were identified. The skill is purely instructional, guiding the user through pricing frameworks without utilizing dangerous tool calls or performing automated background operations.
- [EXTERNAL_DOWNLOADS]: The skill documentation references a third-party plugin at github.com/coreyhaines31/marketingskills. This is presented as a manual recommendation for users who want to extend their marketing capabilities and does not involve automated remote code execution or hidden downloads.
- [PROMPT_INJECTION]: The skill ingests user-supplied business and pricing data to generate custom reports, representing an indirect prompt injection surface (Category 8). Evidence Chain: 1. Ingestion points: User answers to pricing diagnosis and current state analysis questions in SKILL.md. 2. Boundary markers: No delimiters or explicit instructions to ignore nested commands are provided. 3. Capability inventory: The skill is limited to text generation; it has no access to subprocesses, file-system writes, or network operations. 4. Sanitization: No sanitization or validation of the user input is performed. The risk is evaluated as safe given the lack of exploitable capabilities within the skill environment.
Audit Metadata