signup-flow-cro
Pass
Audited by Gen Agent Trust Hub on May 6, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [SAFE]: No malicious patterns or security risks were identified in the skill instructions or metadata. The skill is purely instructional and focused on business logic optimization.
- [SAFE]: The skill does not request or use any dangerous tools, such as those for network access, arbitrary command execution, or sensitive credential management.
- [PROMPT_INJECTION]: The skill instructions create an attack surface for indirect prompt injection via the ingestion of project context files.
- Ingestion points: Reads '.agents/product-marketing-context.md' or '.claude/product-marketing-context.md' at the start of the assessment flow.
- Boundary markers: Absent. The skill does not instruct the agent to ignore or delimit instructions found within these context files.
- Capability inventory: None. The skill generates text-based recommendations and lacks tools for network, file system (write), or subprocess execution.
- Sanitization: Absent. No validation or filtering is applied to the content of the marketing context files.
- Assessment: Due to the lack of actionable tools, this represents a low-risk surface used for legitimate context-gathering and does not escalate the safety verdict.
Audit Metadata