co-marketing

Pass

Audited by Gen Agent Trust Hub on Aug 5, 2026

Risk Level: SAFE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to read external configuration files (e.g., .agents/product-marketing.md) to gather project context. This is a common pattern for context-aware agents but represents a theoretical surface for indirect prompt injection if the content of those files is controlled by an untrusted party.
  • Ingestion points: Instructions in SKILL.md guide the agent to read .agents/product-marketing.md, .claude/product-marketing.md, or product-marketing-context.md at the start of the task.
  • Boundary markers: The instructions do not define specific delimiters or "ignore embedded instructions" warnings for these files.
  • Capability inventory: The skill is documentation-based and does not provide executable scripts or tools that would grant the agent additional system permissions.
  • Sanitization: The skill does not mention specific sanitization or validation logic for the ingested content.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 5, 2026, 04:44 PM
Security Audit — agent-trust-hub — co-marketing