paywall-upgrade-cro

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill facilitates the ingestion and analysis of external data via Python scripts, presenting a surface for indirect prompt injection if the processed JSON files contain malicious instructions.\n
  • Ingestion points: Data is ingested from local JSON files through scripts/paywall_trigger_auditor.py, scripts/upgrade_funnel_analyzer.py, and scripts/paywall_copy_scorer.py.\n
  • Boundary markers: Absent. The skill instructions do not require the agent to use delimiters or 'ignore' instructions to isolate processed data from the system prompt.\n
  • Capability inventory: The skill is limited to local file reads and text analysis. No capabilities for network exfiltration, subprocess spawning, or dynamic code execution were detected in the provided scripts or markdown.\n
  • Sanitization: Absent. The scripts rely on standard JSON parsing and do not filter or sanitize string content for embedded natural language instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 02:10 PM
Security Audit — agent-trust-hub — paywall-upgrade-cro