conversion-optimizer
Pass
Audited by Gen Agent Trust Hub on May 1, 2026
Risk Level: SAFE
Full Analysis
- [DYNAMIC_CONTEXT_INJECTION]: The skill utilizes load-time shell commands to include protocol documents and author-specific settings into the agent's context. These commands use fixed local paths and do not incorporate user-controlled arguments, presenting no command injection risk.
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze external data, including website content from product URLs and application source code. While this creates a surface where an attacker could influence agent behavior through analyzed data, the skill lacks high-privilege tools (such as network egress or arbitrary command execution) that would make such a surface exploitable.
- Ingestion points: Deployed product URL, PRD/BRD documents, and frontend source code.
- Boundary markers: Absent.
- Capability inventory: File system write access limited to generating optimization documentation in the marketing/cro/ directory.
- Sanitization: Not specified.
Audit Metadata