paywall-upgrade-cro
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill facilitates the ingestion and analysis of external data via Python scripts, presenting a surface for indirect prompt injection if the processed JSON files contain malicious instructions.\n
- Ingestion points: Data is ingested from local JSON files through
scripts/paywall_trigger_auditor.py,scripts/upgrade_funnel_analyzer.py, andscripts/paywall_copy_scorer.py.\n - Boundary markers: Absent. The skill instructions do not require the agent to use delimiters or 'ignore' instructions to isolate processed data from the system prompt.\n
- Capability inventory: The skill is limited to local file reads and text analysis. No capabilities for network exfiltration, subprocess spawning, or dynamic code execution were detected in the provided scripts or markdown.\n
- Sanitization: Absent. The scripts rely on standard JSON parsing and do not filter or sanitize string content for embedded natural language instructions.
Audit Metadata