live-dashboard
Warn
Audited by Gen Agent Trust Hub on Apr 1, 2026
Risk Level: MEDIUMDATA_EXFILTRATION
Full Analysis
- [DATA_EXFILTRATION]: The skill is designed to access and read local files that explicitly contain sensitive authentication information.
- Evidence: In the 'Process' section, step 1 specifies reading
~/.claude-marketing/brands/{slug}/profile.jsonto "Extract business model, key metrics... and connected platform credentials." - Evidence: It also accesses
~/.claude-marketing/brands/_active-brand.jsonand~/.claude-marketing/brands/{slug}/guidelines/_manifest.jsonwhich may contain proprietary business logic or strategy. - [DATA_EXFILTRATION]: The skill uses extracted credentials to interact with external marketing platforms (Google Ads, Meta, etc.) via MCP tools.
- Evidence: Process steps 3 and 4 involve mapping data sources and generating configurations for external APIs using the extracted credentials.
Audit Metadata