crisis-response

Pass

Audited by Gen Agent Trust Hub on Apr 1, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill integrates various local configuration and guideline files into the agent's context, which constitutes an indirect prompt injection surface.\n
  • Ingestion points: Data is loaded from ~/.claude-marketing/brands/_active-brand.json, profile.json, _manifest.json, templates, agency SOPs, and skills/context-engine/compliance-rules.md.\n
  • Boundary markers: There are no boundary markers or instructions to the agent to disregard instructions potentially embedded within these brand data files.\n
  • Capability inventory: The ingested content is used to influence narrative analysis and messaging drafting; however, the skill does not define subprocess execution, network operations, or file-write capabilities.\n
  • Sanitization: The skill lacks any steps to validate, escape, or sanitize the content loaded from these external local sources before they are processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 1, 2026, 01:18 AM