co-marketing
Pass
Audited by Gen Agent Trust Hub on Jul 18, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill is configured to ingest project-specific marketing context from local files if they exist in the environment. This creates an indirect prompt injection surface where untrusted data from these files could potentially influence agent behavior.
- Ingestion points:
.agents/product-marketing.md,.claude/product-marketing.md, andproduct-marketing-context.md(as referenced inSKILL.md). - Boundary markers: No specific delimiters or warnings to ignore embedded instructions are provided when reading these files.
- Capability inventory: No dangerous tools such as subprocess execution, dynamic code evaluation, or network exfiltration tools are defined or used within the skill's scripts.
- Sanitization: There is no evidence of sanitization or validation of the ingested content before it is processed by the agent.
Audit Metadata