live-dashboard

Warn

Audited by Gen Agent Trust Hub on Apr 1, 2026

Risk Level: MEDIUMDATA_EXFILTRATION
Full Analysis
  • [DATA_EXFILTRATION]: The skill is designed to access and read local files that explicitly contain sensitive authentication information.
  • Evidence: In the 'Process' section, step 1 specifies reading ~/.claude-marketing/brands/{slug}/profile.json to "Extract business model, key metrics... and connected platform credentials."
  • Evidence: It also accesses ~/.claude-marketing/brands/_active-brand.json and ~/.claude-marketing/brands/{slug}/guidelines/_manifest.json which may contain proprietary business logic or strategy.
  • [DATA_EXFILTRATION]: The skill uses extracted credentials to interact with external marketing platforms (Google Ads, Meta, etc.) via MCP tools.
  • Evidence: Process steps 3 and 4 involve mapping data sources and generating configurations for external APIs using the extracted credentials.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Apr 1, 2026, 01:18 AM