marketing-plan
Pass
Audited by Gen Agent Trust Hub on Jul 9, 2026
Risk Level: SAFE
Full Analysis
- [PROMPT_INJECTION]: The skill exhibits a surface for indirect prompt injection through its ingestion of untrusted client-provided materials (such as pitch decks, transcripts, and prior audits).
- Ingestion points: Data enters the context during the INIT phase by reading files in the
~/marketing-plans/{client-slug}/materials/directory. - Boundary markers: The instructions do not explicitly implement delimiters or markers to distinguish external data from core instructions.
- Capability inventory: The agent leverages tools for local file access and interacts with business-critical APIs (Stripe, GA4, Ahrefs) via MCP integrations.
- Sanitization: No explicit sanitization or filtering of external content is performed before processing.
- [DATA_EXPOSURE]: To fulfill its purpose, the skill accesses sensitive business metrics such as revenue (Stripe), traffic (GA4), and SEO data (Ahrefs). These operations are conducted through the user's authorized tool configurations and are necessary for creating an accurate fCMO-level marketing plan.
- [EXTERNAL_DOWNLOADS]: The documentation references well-known and trusted marketing technology services (e.g., Stripe, Google Analytics, Ahrefs, GitHub, Customer.io). These are documented as part of a standard marketing operations stack and do not involve unauthorized software downloads or remote code execution.
Audit Metadata