marketing-mode

Pass

Audited by Gen Agent Trust Hub on Sep 27, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill requires the installation of the @thesethrose/marketing-mode package from the public NPM registry.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze untrusted user-provided information, such as product descriptions and target audience profiles, to generate marketing strategies and copy.
  • Ingestion points: User input concerning product details, target audience, and marketing goals captured via clarifying questions in SKILL.md and mode-prompt.md.
  • Boundary markers: The instructions lack specific delimiters or isolation techniques to prevent the agent from acting on commands that might be hidden within the marketing data provided by the user.
  • Capability inventory: The skill generates marketing-focused text and frameworks. It requires access to the Node.js runtime environment and the NPM package manager.
  • Sanitization: No data validation or sanitization procedures are specified for the content processed by the skill at runtime.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 27, 2026, 09:32 PM
Security Audit — agent-trust-hub — marketing-mode