saas-metrics-coach

Pass

Audited by Gen Agent Trust Hub on Sep 28, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides standard data processing scripts (Python) to calculate MRR, ARR, churn, and unit economics. These scripts operate locally on user-provided CSV and JSON files and do not perform network requests, execute shell commands, or modify system files.
  • [SAFE]: No obfuscation, prompt injection, or remote code execution patterns were detected.
  • [INDIRECT_PROMPT_INJECTION]: The skill has a data ingestion surface but lacks any dangerous capabilities to exploit it.
  • Ingestion points: Untrusted data enters via CSV files in scripts/mrr_calculator.py and scripts/cohort_analyzer.py, and JSON files in scripts/unit_economics.py.
  • Boundary markers: None provided in instructions or scripts.
  • Capability inventory: All scripts are strictly limited to mathematical calculations and console output; no network access, file system write operations, or command execution capabilities were found.
  • Sanitization: The scripts use standard library CSV and JSON parsers and implement type conversion/validation for all numerical inputs used in calculations.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 28, 2026, 07:29 AM
Security Audit — agent-trust-hub — saas-metrics-coach