marketing-ideas
Pass
Audited by Gen Agent Trust Hub on Aug 10, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill instructions specify reading local context files (
.agents/product-marketing-context.mdor.claude/product-marketing-context.md) to customize its marketing advice. This creates a surface where instructions embedded in those data files could influence the agent's behavior. - Ingestion points:
SKILL.mdexplicitly directs the agent to read product marketing context from local markdown files. - Boundary markers: The instructions lack boundary markers or specific guidance to the agent to ignore any potential instructions found within the ingested context files.
- Capability inventory: The skill is primarily informational and does not define or use any high-risk tools such as network access, shell command execution, or file writing capabilities.
- Sanitization: No sanitization or filtering logic is present to handle potentially malicious content within the context files before they are read by the agent.
Audit Metadata