marketing-plan
Pass
Audited by Gen Agent Trust Hub on Aug 11, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill follows professional standards for marketing strategy and fractional CMO operations. No malicious patterns, such as prompt injection, obfuscation, or persistence mechanisms, were detected.
- [COMMAND_EXECUTION]: The skill instructs the agent to use various tools including
agent-browser,gh(GitHub CLI), and multiple MCP integrations (Stripe, Ahrefs, GA4, Customer.io). These actions are consistent with the skill's stated purpose of conducting research, pulling analytics, and publishing strategy documents. - [DATA_EXFILTRATION]: While the skill accesses sensitive business metrics (revenue, churn, traffic) and interacts with external APIs, these operations are central to its function as a marketing strategist. The instructions explicitly recommend using
.envfiles for secret management, which is a security best practice. - [PROMPT_INJECTION]: The skill processes external client materials (decks, audits, transcripts). While this creates a surface for indirect prompt injection, the risk is mitigated by the structured nature of the intake process and the agent's role as a strategist synthesizing data rather than blindly executing external commands.
Audit Metadata