marketing-psychology

Pass

Audited by Gen Agent Trust Hub on May 6, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill is designed to analyze untrusted external data (such as landing pages, marketing assets, or campaign flows) in its 'Diagnose' and 'Apply' modes. This creates an indirect prompt injection surface where malicious instructions embedded in the analyzed content could potentially influence the agent's behavior.
  • Ingestion points: External marketing assets, pages, or campaign flows processed via the instructions in SKILL.md (Mode 1 and Mode 2).
  • Boundary markers: The instructions do not define clear delimiters (e.g., XML tags or backticks) or include warnings to the agent to ignore instructions embedded within the processed data.
  • Capability inventory: While this skill primarily generates text, it mentions integration with other skills like page-cro and ab-test-setup, which may have broader system access or tool execution capabilities.
  • Sanitization: There is no mention of sanitizing, escaping, or validating the input provided for analysis.
Audit Metadata
Risk Level
SAFE
Analyzed
May 6, 2026, 01:52 AM
Security Audit — agent-trust-hub — marketing-psychology