creator-programme-qbr
Pass
Audited by Gen Agent Trust Hub on Jul 28, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill contains no code or instructions that perform unauthorized actions, network exfiltration, or credential harvesting. The workflow is restricted to processing campaign metrics and generating a report template.
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from external campaign records and analytics sources, which is a potential surface for indirect prompt injection.
- Ingestion points: Campaign performance records (spreadsheets, CRM) and creator-analytics sources referenced in Step 0.
- Boundary markers: The instructions do not define specific delimiters or instructions to ignore embedded commands within the processed data.
- Capability inventory: The skill's capabilities are limited to text generation and data synthesis within the agent context; no dangerous subprocess calls, file writes, or network operations are utilized.
- Sanitization: There are no explicit sanitization or validation steps for the external content mentioned in the workflow.
Audit Metadata