conversion-value-mapper

Pass

Audited by Gen Agent Trust Hub on Aug 20, 2026

Risk Level: SAFE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes potentially untrusted external data (GA4 and ecommerce CSV exports). It includes explicit security instructions to treat this data as untrusted evidence rather than commands, and emphasizes boundary markers between the user's data and the agent's instructions. The vulnerability surface is low as the task is purely analytical (calculating margins and values).
  • [REMOTE_CODE_EXECUTION]: No remote code execution or package installation patterns were detected. The skill uses standard markdown and logical instructions without executable scripts.
  • [DATA_EXFILTRATION]: The skill operates on user-provided data exports and writes results to a local memory/ directory. No network operations or non-whitelisted domain requests are present.
  • [COMMAND_EXECUTION]: The skill does not invoke shell commands, subprocesses, or dynamic execution environments.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 20, 2026, 07:28 PM
Security Audit — agent-trust-hub — conversion-value-mapper