form-cro
Pass
Audited by Gen Agent Trust Hub on Apr 22, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill consists entirely of markdown documentation and evaluation datasets. It contains no code, scripts, or external dependencies.
- [DATA_EXPOSURE]: The skill references a local context file (.agents/product-marketing-context.md) to gather project-specific information. This is a standard pattern for context-aware AI agents and does not involve accessing sensitive system credentials or private keys.
- [INDIRECT_PROMPT_INJECTION]: The skill provides a surface for indirect prompt injection. 1. Ingestion points: .agents/product-marketing-context.md. 2. Boundary markers: Absent. 3. Capability inventory: No dangerous capabilities (no subprocess, no file-write, no network operations) identified across all instructions. 4. Sanitization: Absent. As the skill lacks exploitable capabilities, this ingestion point does not pose a functional risk.
Audit Metadata