create-an-asset

Pass

Audited by Gen Agent Trust Hub on Apr 7, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill's core functionality involves gathering context and generating HTML-based sales assets, which aligns with its documented purpose.
  • [DATA_EXFILTRATION]: The skill identifies the user's company domain and performs targeted web searches for brand guidelines and strategic information. These activities use standard agent tools for information retrieval and do not target sensitive local files or private data.
  • [PROMPT_INJECTION]: The skill ingests untrusted external data in the form of conversation transcripts and email threads to tailor sales messaging.\n
  • Ingestion points: User-uploaded materials such as call recordings, transcripts, and email threads (referenced in SKILL.md and README.md).\n
  • Boundary markers: The instructions do not specify the use of delimiters or specific system-level instructions to ignore embedded commands within the uploaded text.\n
  • Capability inventory: The skill has the capability to perform web searches and write files to the local environment (HTML assets).\n
  • Sanitization: There is no explicit mention of sanitizing or filtering content extracted from the transcripts before it is used to generate the final asset code.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 7, 2026, 03:21 PM
Security Audit — agent-trust-hub — create-an-asset