form-cro
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill includes instructions to execute three local Python scripts:
form_scorer.py,field_cost_analyzer.py, andab_test_calculator.py. These scripts are part of the skill package and perform benign statistical calculations, ROI assessments, and configuration audits based on user-provided inputs. - [INDIRECT_PROMPT_INJECTION]: The skill processes external data in the form of JSON configuration files (e.g.,
form_config.json,form_fields.json) provided by the user or project environment. The included scripts ingest this data as structured JSON to perform calculations, which represents a minimal attack surface as the data is not interpolated into natural language prompts or used for dynamic code execution.
Audit Metadata