crisis-response
Pass
Audited by Gen Agent Trust Hub on Apr 1, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill integrates various local configuration and guideline files into the agent's context, which constitutes an indirect prompt injection surface.\n
- Ingestion points: Data is loaded from
~/.claude-marketing/brands/_active-brand.json,profile.json,_manifest.json, templates, agency SOPs, andskills/context-engine/compliance-rules.md.\n - Boundary markers: There are no boundary markers or instructions to the agent to disregard instructions potentially embedded within these brand data files.\n
- Capability inventory: The ingested content is used to influence narrative analysis and messaging drafting; however, the skill does not define subprocess execution, network operations, or file-write capabilities.\n
- Sanitization: The skill lacks any steps to validate, escape, or sanitize the content loaded from these external local sources before they are processed by the agent.
Audit Metadata