marketing-product-marketing

Pass

Audited by Gen Agent Trust Hub on Aug 8, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: No security issues were identified in the skill's workflow. Its operations are confined to the local project environment for the purpose of documentation management.
  • [PROMPT_INJECTION]: The skill design includes an indirect prompt injection surface due to its requirement to ingest data from the repository's codebase.
  • Ingestion points: The skill scans files such as README, landing pages, and package.json to auto-draft content.
  • Boundary markers: The instructions do not specify the use of delimiters to separate or qualify the ingested codebase content.
  • Capability inventory: The skill is limited to reading local files and writing the marketing context to .agents/product-marketing.md; it has no network or shell execution capabilities.
  • Sanitization: The skill does not implement specific sanitization or filtering for the data read from the codebase.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 8, 2026, 02:46 PM
Security Audit — agent-trust-hub — marketing-product-marketing