marketing-ideas

Pass

Audited by Gen Agent Trust Hub on Aug 10, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill instructions specify reading local context files (.agents/product-marketing-context.md or .claude/product-marketing-context.md) to customize its marketing advice. This creates a surface where instructions embedded in those data files could influence the agent's behavior.
  • Ingestion points: SKILL.md explicitly directs the agent to read product marketing context from local markdown files.
  • Boundary markers: The instructions lack boundary markers or specific guidance to the agent to ignore any potential instructions found within the ingested context files.
  • Capability inventory: The skill is primarily informational and does not define or use any high-risk tools such as network access, shell command execution, or file writing capabilities.
  • Sanitization: No sanitization or filtering logic is present to handle potentially malicious content within the context files before they are read by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 10, 2026, 01:27 PM
Security Audit — agent-trust-hub — marketing-ideas