marketing-skills-collection
Pass
Audited by Gen Agent Trust Hub on Mar 23, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill is a template-driven marketing assistant. All instructions and examples are focused on benign business use cases such as conversion rate optimization and copywriting.
- [PROMPT_INJECTION]: No patterns of safety bypass, role-play injection, or instruction override were detected. The use of 'IMPORTANT' in developer instructions is strictly for guidance and does not attempt to subvert the agent's core safety logic.
- [DATA_EXFILTRATION]: The skill does not access sensitive local file paths (e.g., .ssh, .aws) and does not contain logic to transmit user data to external, non-whitelisted domains. The 'analytics-tracking' sub-skill focuses on defining tracking events for user web-analytics platforms, not exfiltrating agent context.
- [REMOTE_CODE_EXECUTION]: There is no evidence of remote script downloads (e.g., curl|bash), package installations, or dynamic code execution (eval/exec) from untrusted sources. Reference to 'Codex' for tracking code generation is treated as a standard agent role for producing code snippets for the user to implement manually.
- [INDIRECT_PROMPT_INJECTION]: The skill has a surface for indirect prompt injection as it utilizes the 'WebFetch' tool to process external content and takes user-provided product context. However, this is inherent to its function as a marketing tool.
- Ingestion points: WebFetch tool and user-supplied product context in Step 3.
- Boundary markers: Absent.
- Capability inventory: Write, Read, WebFetch, Task.
- Sanitization: Absent.
Audit Metadata