pm-brand-strategy
Pass
Audited by Gen Agent Trust Hub on Jun 23, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill performs legitimate project-level tasks such as reading common configuration files (package.json, pyproject.toml) and writing a brand strategy file to the
.claude/directory. No unauthorized access to sensitive system directories or credentials was found. - [COMMAND_EXECUTION]: The skill does not use any shell execution commands or dynamic code evaluation. It operates purely as a text-processing and file-generation tool.
- [PROMPT_INJECTION]: The skill includes an 'Auto-Draft' mode that reads untrusted project files (like README.md). This creates a surface for indirect prompt injection where malicious content in those files could influence the generated marketing strategy. However, the impact is low as the skill's capabilities are confined to writing markdown documentation within the project scope.
- Ingestion points:
README,package.json,pyproject.toml,CONTRIBUTING.mdinSKILL.md. - Boundary markers: Absent.
- Capability inventory: Writes to
.claude/product-marketing-context.mdinSKILL.md. - Sanitization: Absent.
Audit Metadata