marketing-plan

Pass

Audited by Gen Agent Trust Hub on Aug 11, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill follows professional standards for marketing strategy and fractional CMO operations. No malicious patterns, such as prompt injection, obfuscation, or persistence mechanisms, were detected.
  • [COMMAND_EXECUTION]: The skill instructs the agent to use various tools including agent-browser, gh (GitHub CLI), and multiple MCP integrations (Stripe, Ahrefs, GA4, Customer.io). These actions are consistent with the skill's stated purpose of conducting research, pulling analytics, and publishing strategy documents.
  • [DATA_EXFILTRATION]: While the skill accesses sensitive business metrics (revenue, churn, traffic) and interacts with external APIs, these operations are central to its function as a marketing strategist. The instructions explicitly recommend using .env files for secret management, which is a security best practice.
  • [PROMPT_INJECTION]: The skill processes external client materials (decks, audits, transcripts). While this creates a surface for indirect prompt injection, the risk is mitigated by the structured nature of the intake process and the agent's role as a strategist synthesizing data rather than blindly executing external commands.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 11, 2026, 10:19 PM
Security Audit — agent-trust-hub — marketing-plan