analytics-tracking
Pass
Audited by Gen Agent Trust Hub on Feb 20, 2026
Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
- [Indirect Prompt Injection] (LOW): The skill identifies and reads an external file .claude/product-marketing-context.md to gather context for its advice. 1. Ingestion points: SKILL.md references and reads .claude/product-marketing-context.md. 2. Boundary markers: Absent; no specific instructions exist to ignore embedded commands within this context file. 3. Capability inventory: SAFE; the skill has no shell execution, file-write, or network capabilities. 4. Sanitization: Absent.
- [No Code] (SAFE): This skill is composed entirely of markdown documentation, tracking templates, and reference guides, and does not contain any executable scripts or system commands.
Audit Metadata