form-cro

Pass

Audited by Gen Agent Trust Hub on Aug 21, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill operates solely as a set of analytical and consultative instructions for form optimization. It does not contain executable scripts, perform network operations, or request access to sensitive system resources.\n- [INDIRECT_PROMPT_INJECTION]: The skill includes instructions to ingest information from a local context file to tailor its recommendations. While this introduces a data ingestion surface, the risk is negligible as the skill lacks capabilities to perform harmful actions.\n
  • Ingestion points: .claude/product-marketing-context.md (referenced in SKILL.md).\n
  • Boundary markers: None; the agent is directed to read the file for context.\n
  • Capability inventory: None; the skill does not utilize subprocess calls, file writing, or network operations.\n
  • Sanitization: None; the skill relies on the existing safety guardrails of the underlying model.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 21, 2026, 02:29 PM
Security Audit — agent-trust-hub — form-cro