marketing-referrals
Pass
Audited by Gen Agent Trust Hub on Aug 8, 2026
Risk Level: SAFENO_CODE
Full Analysis
- [NO_CODE]: The skill package is composed exclusively of Markdown documentation, evaluation data in JSON format, and standard metadata. It does not include Python scripts, Node.js modules, shell scripts, or any other form of executable logic.
- [SAFE]: No malicious patterns were identified. There is no evidence of credential harvesting, unauthorized network communication, or attempts to bypass agent safety guidelines. The skill mentions reputable third-party services (such as Stripe, Rewardful, and PartnerStack) solely for legitimate business tool recommendations.
- [PROMPT_INJECTION]: The skill instructions advise the agent to read local context files (e.g.,
.agents/product-marketing.md) if available. While this creates a theoretical ingestion point for untrusted data (Indirect Prompt Injection surface), the skill lacks any operational tools or capabilities—such as file writing, network requests, or command execution—that could be abused by an injection, rendering the surface safe for use.
Audit Metadata