marketing-plan

Pass

Audited by Gen Agent Trust Hub on Jul 7, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill possesses an indirect prompt injection surface due to its research and generation workflow.
  • Ingestion points: The agent ingests untrusted client materials (e.g., pitch decks, transcripts, audits) from the ~/marketing-plans/{client-slug}/materials/ directory.
  • Boundary markers: The instructions lack explicit delimiters or specific directives to the agent to ignore embedded instructions within these external materials.
  • Capability inventory: The skill has the capability to modify GitHub repositories via the GitHub MCP and dispatch emails using the Customer.io MCP.
  • Sanitization: No verification or sanitization of the external content is performed before it is processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 7, 2026, 04:35 AM
Security Audit — agent-trust-hub — marketing-plan