marketing-sms

Pass

Audited by Gen Agent Trust Hub on Aug 8, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill is designed to ingest business context from local files such as .agents/product-marketing.md. This presents an indirect prompt injection surface where untrusted content in those files could be used to manipulate the agent's strategy or the SMS copy it generates.
  • Ingestion points: The skill specifically instructs the agent to read .agents/product-marketing.md, .claude/product-marketing.md, or product-marketing-context.md at the start of a task.
  • Boundary markers: The instructions do not define boundary markers or include instructions to treat the ingested file content strictly as data rather than as instructions.
  • Capability inventory: The agent uses this context to design SMS marketing plans, create message sequences, and recommend software platforms.
  • Sanitization: There is no logic provided to sanitize or validate the content of the marketing context files before they are processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 8, 2026, 02:46 PM
Security Audit — agent-trust-hub — marketing-sms