marketing-product-marketing
Pass
Audited by Gen Agent Trust Hub on Aug 8, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: No security issues were identified in the skill's workflow. Its operations are confined to the local project environment for the purpose of documentation management.
- [PROMPT_INJECTION]: The skill design includes an indirect prompt injection surface due to its requirement to ingest data from the repository's codebase.
- Ingestion points: The skill scans files such as README, landing pages, and package.json to auto-draft content.
- Boundary markers: The instructions do not specify the use of delimiters to separate or qualify the ingested codebase content.
- Capability inventory: The skill is limited to reading local files and writing the marketing context to .agents/product-marketing.md; it has no network or shell execution capabilities.
- Sanitization: The skill does not implement specific sanitization or filtering for the data read from the codebase.
Audit Metadata