product-marketing-context
Pass
Audited by Gen Agent Trust Hub on Sep 5, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill analyzes external content (README, landing pages, marketing copy) to auto-draft a context document, which presents an attack surface where malicious instructions could be embedded in the processed data.
- Ingestion points: The skill reads
README.md,package.json, and other documentation files within the user's repository. - Boundary markers: None specified in the instructions for separating codebase content from agent instructions during analysis.
- Capability inventory: The skill performs file system reads and writes to
.agents/product-marketing-context.md. - Sanitization: No explicit sanitization or filtering of codebase content is mentioned before it is processed into the draft.
Audit Metadata