paywall-optimization

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFENO_CODE
Full Analysis
  • [SAFE]: The skill is entirely instructional. It provides a structured methodology for auditing and A/B testing mobile application paywalls using industry-standard frameworks (RevenueCat, Superwall, Adapty).
  • [NO_CODE]: No scripts, executables, or package dependencies are included or referenced in the skill body.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to process external data including project-specific marketing files (app-marketing-context.md) and user-provided subscription metrics.
  • Ingestion points: Reads app-marketing-context.md and accepts App IDs and metrics as user input.
  • Boundary markers: None explicitly defined in the instructions.
  • Capability inventory: No file system writes, network requests, or shell command executions are present in the skill.
  • Sanitization: None specified.
  • Risk: Since the skill lacks tool-based capabilities, the potential for indirect prompt injection to cause harm is negligible.
  • [DATA_EXPOSURE]: The skill requests App IDs and subscription metrics to perform its task. This is consistent with its stated purpose of conversion optimization and does not involve exfiltration to third-party domains or hardcoded credentials.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 12:50 PM
Security Audit — agent-trust-hub — paywall-optimization