influencer-marketing
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: No malicious patterns, obfuscation, or dangerous execution capabilities were identified. The skill is entirely composed of text-based strategic frameworks and guidance for marketing professionals. All mentioned third-party tools (Stormy.ai, Upfluence, Passionfroot) are well-known industry platforms.
- [INDIRECT_PROMPT_INJECTION]: The skill identifies an attack surface by instructing the agent to read local project context files to tailor its advice. * Ingestion points: .claude/project-context.md and .cursor/project-context.md (identified in Initial Assessment). * Boundary markers: Absent. * Capability inventory: None (the skill has no access to tools for command execution, file modification, or network exfiltration). * Sanitization: Absent. * Note: This context-gathering behavior is standard for project-aware agents and does not pose a security risk in this context as the skill lacks any capabilities that could be exploited by malicious content within those files.
Audit Metadata