creator-programme-qbr

Pass

Audited by Gen Agent Trust Hub on Jul 28, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill contains no code or instructions that perform unauthorized actions, network exfiltration, or credential harvesting. The workflow is restricted to processing campaign metrics and generating a report template.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from external campaign records and analytics sources, which is a potential surface for indirect prompt injection.
  • Ingestion points: Campaign performance records (spreadsheets, CRM) and creator-analytics sources referenced in Step 0.
  • Boundary markers: The instructions do not define specific delimiters or instructions to ignore embedded commands within the processed data.
  • Capability inventory: The skill's capabilities are limited to text generation and data synthesis within the agent context; no dangerous subprocess calls, file writes, or network operations are utilized.
  • Sanitization: There are no explicit sanitization or validation steps for the external content mentioned in the workflow.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 28, 2026, 04:39 PM
Security Audit — agent-trust-hub — creator-programme-qbr