marketing-sms
Pass
Audited by Gen Agent Trust Hub on Aug 8, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill is designed to ingest business context from local files such as
.agents/product-marketing.md. This presents an indirect prompt injection surface where untrusted content in those files could be used to manipulate the agent's strategy or the SMS copy it generates. - Ingestion points: The skill specifically instructs the agent to read
.agents/product-marketing.md,.claude/product-marketing.md, orproduct-marketing-context.mdat the start of a task. - Boundary markers: The instructions do not define boundary markers or include instructions to treat the ingested file content strictly as data rather than as instructions.
- Capability inventory: The agent uses this context to design SMS marketing plans, create message sequences, and recommend software platforms.
- Sanitization: There is no logic provided to sanitize or validate the content of the marketing context files before they are processed by the agent.
Audit Metadata