marketing-psychology
Pass
Audited by Gen Agent Trust Hub on May 6, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill is designed to analyze untrusted external data (such as landing pages, marketing assets, or campaign flows) in its 'Diagnose' and 'Apply' modes. This creates an indirect prompt injection surface where malicious instructions embedded in the analyzed content could potentially influence the agent's behavior.
- Ingestion points: External marketing assets, pages, or campaign flows processed via the instructions in
SKILL.md(Mode 1 and Mode 2). - Boundary markers: The instructions do not define clear delimiters (e.g., XML tags or backticks) or include warnings to the agent to ignore instructions embedded within the processed data.
- Capability inventory: While this skill primarily generates text, it mentions integration with other skills like
page-croandab-test-setup, which may have broader system access or tool execution capabilities. - Sanitization: There is no mention of sanitizing, escaping, or validating the input provided for analysis.
Audit Metadata