paywall-upgrade-cro
Pass
Audited by Gen Agent Trust Hub on Apr 16, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill instructions direct the agent to read local context files (
.agents/product-marketing-context.mdor.claude/product-marketing-context.md) to personalize its advice. This represents a potential surface for indirect prompt injection if an attacker controls those local files. However, the risk is negligible as the skill lacks high-privilege capabilities. - Ingestion points:
SKILL.mdreferences reading.agents/product-marketing-context.mdand.claude/product-marketing-context.md. - Boundary markers: None present in the instructions.
- Capability inventory: The skill is restricted to providing text-based recommendations and copy analysis; no shell execution, file-writing, or network operations are requested or used.
- Sanitization: No explicit sanitization of the context file content is defined.
Audit Metadata