campaign-and-launch-planning
Pass
Audited by Gen Agent Trust Hub on Jul 18, 2026
Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface due to its data ingestion workflow.\n
- Ingestion points: The skill is instructed to process external data sources including
brand-profile,goals-and-kpis, andcompetitor-analysisto inform campaign planning (SKILL.md, references/scope-and-connections.md).\n - Boundary markers: The instructions do not define explicit boundary markers or instructions to disregard embedded commands when reading these external files.\n
- Capability inventory: The agent has the capability to publish and schedule social media posts via the
WoopSocialintegration (usingSCHEDULE_FOR_LATER), which could be misused if ingested data contains malicious instructions.\n - Sanitization: No specific content sanitization or validation routines are described to prevent instructions within input files from overriding the agent's behavior during content generation.\n- [COMMAND_EXECUTION]: The skill facilitates the execution of social media management actions through a third-party tool.\n
- Evidence: The instructions explicitly describe using the
WoopSocialtool to schedule and publish coordinated posts on connected platforms (SKILL.md, references/the-story-framework.md). This involves the agent translating its plans into executable scheduling commands for an external publishing engine.
Audit Metadata