positioning-messaging-designer
Pass
Audited by Gen Agent Trust Hub on Jul 30, 2026
Risk Level: SAFE
Full Analysis
- [PROMPT_INJECTION]: The skill contains no attempts to override agent behavior, bypass safety filters, or extract system prompts. All instructions are aligned with the primary purpose of positioning and messaging design.- [DATA_EXFILTRATION]: No hardcoded credentials, sensitive file paths, or unauthorized network operations were found. The skill includes a single plain-text URL to a legitimate podcast episode for instructional context, which does not involve data exfiltration.- [REMOTE_CODE_EXECUTION]: The skill does not download or execute external scripts, and no package installation commands (npm, pip) are present.- [COMMAND_EXECUTION]: No dangerous shell commands, privilege escalation (sudo), or persistence mechanisms (cron, bashrc) were detected.- [OBFUSCATION]: No Base64, zero-width characters, homoglyphs, or other forms of text encoding/obfuscation were found in the skill or its reference files.- [DYNAMIC_EXECUTION]: The skill does not generate or execute code at runtime. It mentions AI integration conceptually as part of a methodology but does not perform any dynamic code evaluation.- [INDIRECT_PROMPT_INJECTION]: While the skill processes user-supplied customer data (SPICED data), it has a low capability tier, primarily generating text frameworks without write access to the filesystem or execution of shell commands. The risk is minimized by the generative nature of the task.
Audit Metadata