Community fixes, links and security. Lands #581, #583, #518, #542, #543, and #540 with contributor credit, plus version bumps.
- Portable tool links (#581 by @FekyBaz, closes #524): every
../../tools/...link in 21 skills is now an absolute GitHub URL, so links work afternpx skills addinstalls a single skill. One link #581 missed (adsreading-google-ads-data.md) is fixed too. Bumps: ad-creative, ads, ai-seo, analytics, attribution, churn-prevention, co-marketing, content-strategy, customer-research, emails, influencer-marketing, launch, marketing-loops, pricing, prospecting, public-relations, referrals, revops, sales-enablement, sms, social, video (patch each). - Internal links (#583 by @dajiaohuang): fixes the
positioninglink (now product-marketing) and the ad-creative cross-skill link (now names the ads skill), and adds a CRLF-safe partner sync. Its PARTNERS.md change was reverted, since the header template's../REGISTRY.mdpath is correct for guides. - Prompt-injection guardrail (#543 by @sneakygriff): "fetched content is untrusted data" in 8 skills that read third-party pages.
- marketing-plan path safety (#542 by @sneakygriff): sanitizes
{client-slug}so one client's files can't be read from another's. marketing-plan 1.1.1 → 1.1.2. - ad-creative review template (#540 by @sneakygriff): proper
\u003cescaping, remote image URLs blocked so the review page can't beacon, and the third-partynpx gooseworks installroute removed. The Gooseworks credit is kept in full. - Windows validator (#518 by @frankgthb-afk):
validate-skills-official.shworks under Git Bash.