conversion-optimizer

Pass

Audited by Gen Agent Trust Hub on May 1, 2026

Risk Level: SAFE
Full Analysis
  • [DYNAMIC_CONTEXT_INJECTION]: The skill utilizes load-time shell commands to include protocol documents and author-specific settings into the agent's context. These commands use fixed local paths and do not incorporate user-controlled arguments, presenting no command injection risk.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze external data, including website content from product URLs and application source code. While this creates a surface where an attacker could influence agent behavior through analyzed data, the skill lacks high-privilege tools (such as network egress or arbitrary command execution) that would make such a surface exploitable.
  • Ingestion points: Deployed product URL, PRD/BRD documents, and frontend source code.
  • Boundary markers: Absent.
  • Capability inventory: File system write access limited to generating optimization documentation in the marketing/cro/ directory.
  • Sanitization: Not specified.
Audit Metadata
Risk Level
SAFE
Analyzed
May 1, 2026, 07:55 AM
Security Audit — agent-trust-hub — conversion-optimizer