referrals

Pass

Audited by Gen Agent Trust Hub on Oct 3, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill focuses on providing marketing advice, templates, and frameworks for growth strategies. It contains no executable code, network exfiltration attempts, or privilege escalation patterns.
  • [INDIRECT_PROMPT_INJECTION]: The skill includes instructions to read project-specific context from local files such as .agents/product-marketing.md. This represents a data ingestion surface; however, the skill's lack of dangerous capabilities (like command execution or external network requests) makes this a standard functional pattern rather than a security risk.
  • Ingestion points: SKILL.md (reads .agents/product-marketing.md or .claude/product-marketing.md).
  • Boundary markers: Absent.
  • Capability inventory: Limited to generating text-based marketing advice and strategy responses.
  • Sanitization: Absent.
  • [SAFE]: The skill references numerous well-known industry tools (e.g., Stripe, HubSpot, Rewardful, PartnerStack) and provides links to internal integration guides. These references are purely informational and follow best practices for tool discovery within an agent environment.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 3, 2026, 11:14 AM
Security Audit — agent-trust-hub — referrals