cpo-advisor
Pass
Audited by Gen Agent Trust Hub on Sep 4, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill includes two Python scripts,
scripts/pmf_scorer.pyandscripts/portfolio_analyzer.py, which are intended to be executed by the agent or user to process product data. These scripts use only standard Python libraries (json, sys, argparse, math) and perform no network operations or dynamic code execution. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to process external data sources such as
company-context.mdand user-supplied JSON files. This represents a standard attack surface where malicious instructions could be embedded in the ingested data to influence agent behavior. However, the skill does not exhibit any specific vulnerabilities or patterns that would escalate this beyond a baseline risk. - [METADATA_POISONING]: The author name 'Alireza Rezvani' in the metadata differs from the assigned author 'alvindean' in the provided context. This is noted as a potential metadata inconsistency but does not appear to be deceptive or malicious in the context of this skill's functionality.
Audit Metadata