ab-test
Pass
Audited by Gen Agent Trust Hub on May 4, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill appears to be a legitimate tool for generating A/B test variations for marketing purposes.
- [DATA_EXPOSURE]: The skill reads from local configuration files such as
core/global-constraints.jsonandcore/marketing-triggers.json. These appear to be internal guidance files and do not contain sensitive user data or credentials. - [PROMPT_INJECTION]: The skill uses a role-play prompt ('Masterpiece A/B Test Generation Engine'), which is a standard technique for guiding agent behavior and does not attempt to bypass safety filters or override system instructions.
- [INDIRECT_PROMPT_INJECTION]: The skill processes user input via the
$ARGUMENTSparameter without explicit boundary markers. However, since the skill has no access to dangerous tools (such as shell execution, network access, or file writing), the risk of indirect prompt injection is negligible.
Audit Metadata