signup-flow-cro

Pass

Audited by Gen Agent Trust Hub on May 6, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [SAFE]: No malicious patterns or security risks were identified in the skill instructions or metadata. The skill is purely instructional and focused on business logic optimization.
  • [SAFE]: The skill does not request or use any dangerous tools, such as those for network access, arbitrary command execution, or sensitive credential management.
  • [PROMPT_INJECTION]: The skill instructions create an attack surface for indirect prompt injection via the ingestion of project context files.
  • Ingestion points: Reads '.agents/product-marketing-context.md' or '.claude/product-marketing-context.md' at the start of the assessment flow.
  • Boundary markers: Absent. The skill does not instruct the agent to ignore or delimit instructions found within these context files.
  • Capability inventory: None. The skill generates text-based recommendations and lacks tools for network, file system (write), or subprocess execution.
  • Sanitization: Absent. No validation or filtering is applied to the content of the marketing context files.
  • Assessment: Due to the lack of actionable tools, this represents a low-risk surface used for legitimate context-gathering and does not escalate the safety verdict.
Audit Metadata
Risk Level
SAFE
Analyzed
May 6, 2026, 08:59 AM
Security Audit — agent-trust-hub — signup-flow-cro