marketing-operations

Pass

Audited by Gen Agent Trust Hub on Sep 5, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONNO_CODE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill establishes workflows for the agent to ingest and qualify external data, such as lead information, SPICED framework responses, and customer interview transcripts. This ingestion of untrusted data creates a potential surface for indirect prompt injection attacks. * Ingestion points: Processes user-provided lead data, chat-based qualification answers, and external customer interview records. * Boundary markers: The skill uses standard markdown structure but lacks explicit instructions for the agent to treat external lead data as untrusted or to ignore potentially embedded instructions. * Capability inventory: While no specific tools are invoked in the skill's text, the agent operates with default environment capabilities (file system and shell access) while interpreting these inputs. * Sanitization: There are no defined procedures for sanitizing or validating the data collected from external prospects or interview subjects before processing.
  • [NO_CODE]: The skill consists entirely of markdown documentation, strategic frameworks, and process definitions. It contains no executable scripts (Python, JavaScript, etc.), binary files, or automated command-line instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 5, 2026, 06:44 AM
Security Audit — agent-trust-hub — marketing-operations