marketing-skills-collection

Pass

Audited by Gen Agent Trust Hub on Mar 23, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is a template-driven marketing assistant. All instructions and examples are focused on benign business use cases such as conversion rate optimization and copywriting.
  • [PROMPT_INJECTION]: No patterns of safety bypass, role-play injection, or instruction override were detected. The use of 'IMPORTANT' in developer instructions is strictly for guidance and does not attempt to subvert the agent's core safety logic.
  • [DATA_EXFILTRATION]: The skill does not access sensitive local file paths (e.g., .ssh, .aws) and does not contain logic to transmit user data to external, non-whitelisted domains. The 'analytics-tracking' sub-skill focuses on defining tracking events for user web-analytics platforms, not exfiltrating agent context.
  • [REMOTE_CODE_EXECUTION]: There is no evidence of remote script downloads (e.g., curl|bash), package installations, or dynamic code execution (eval/exec) from untrusted sources. Reference to 'Codex' for tracking code generation is treated as a standard agent role for producing code snippets for the user to implement manually.
  • [INDIRECT_PROMPT_INJECTION]: The skill has a surface for indirect prompt injection as it utilizes the 'WebFetch' tool to process external content and takes user-provided product context. However, this is inherent to its function as a marketing tool.
  • Ingestion points: WebFetch tool and user-supplied product context in Step 3.
  • Boundary markers: Absent.
  • Capability inventory: Write, Read, WebFetch, Task.
  • Sanitization: Absent.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 23, 2026, 05:38 PM