page-metadata
Pass
Audited by Gen Agent Trust Hub on Mar 12, 2026
Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
- [PROMPT_INJECTION]: The skill instructions specify reading external data from '.claude/product-marketing-context.md' or '.cursor/product-marketing-context.md', establishing a surface for indirect prompt injection where malicious instructions could be embedded in those files. Ingestion points: '.claude/product-marketing-context.md' and '.cursor/product-marketing-context.md' identified in SKILL.md. Boundary markers: Absent from the instructions. Capability inventory: The skill is limited to generating SEO-related text strings (HTML/TSX); no subprocess execution, network operations, or file-system modification capabilities were detected. Sanitization: Absent.
- [NO_CODE]: This skill contains no executable code, scripts, or binaries; it consists entirely of markdown instructions and documentation for the agent.
Audit Metadata