signup-flow-cro
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill and its associated scripts are focused on legitimate business growth and optimization tasks. No security issues were identified across the 11 threat categories.
- [COMMAND_EXECUTION]: The skill includes three Python scripts in the
scripts/directory (signup_field_auditor.py,signup_flow_scorer.py,cc_requirement_analyzer.py) which are intended to be executed on local JSON data files. These scripts use standard Python libraries (json,argparse,sys) to perform analysis and do not execute arbitrary shell commands or perform unsafe operations. - [DATA_EXFILTRATION]: There are no network operations, hardcoded credentials, or instructions to access sensitive file paths (such as
.envor SSH keys). All scripts operate on local input data and return formatted text or JSON results. - [INDIRECT_PROMPT_INJECTION]: The skill processes user-supplied configuration files through its analysis scripts. This creates an ingestion surface for external data, but the scripts implement strict logic for parsing and reporting, posing no significant risk of prompt injection or guardrail bypass.
Audit Metadata