marketing-expert

Warn

Audited by Gen Agent Trust Hub on Feb 16, 2026

Risk Level: MEDIUMPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [Indirect Prompt Injection] (MEDIUM): The skill is designed to analyze external data sources which could contain malicious instructions.
  • Ingestion points: 'Funnel Diagnostics' protocol and 'scripts/lint-cro-check.ts' which scans webpages.
  • Boundary markers: None; the instructions do not establish delimiters or tell the agent to ignore instructions within analyzed content.
  • Capability inventory: Execution of local Python and TypeScript scripts (scripts/calculate-clv.py, scripts/lint-cro-check.ts).
  • Sanitization: No evidence of content escaping or validation before data is passed to scripts or reasoning steps.
  • [Command Execution] (LOW): The skill invokes external scripts for data processing. While no malicious payload is identified in the markdown, the logic within 'scripts/calculate-clv.py' and 'scripts/lint-cro-check.ts' is opaque and unverified.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Feb 16, 2026, 05:34 AM