co-marketing
Pass
Audited by Gen Agent Trust Hub on Aug 5, 2026
Risk Level: SAFE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to read external configuration files (e.g.,
.agents/product-marketing.md) to gather project context. This is a common pattern for context-aware agents but represents a theoretical surface for indirect prompt injection if the content of those files is controlled by an untrusted party. - Ingestion points: Instructions in
SKILL.mdguide the agent to read.agents/product-marketing.md,.claude/product-marketing.md, orproduct-marketing-context.mdat the start of the task. - Boundary markers: The instructions do not define specific delimiters or "ignore embedded instructions" warnings for these files.
- Capability inventory: The skill is documentation-based and does not provide executable scripts or tools that would grant the agent additional system permissions.
- Sanitization: The skill does not mention specific sanitization or validation logic for the ingested content.
Audit Metadata