paywall-upgrade-cro

Pass

Audited by Gen Agent Trust Hub on Apr 16, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill instructions direct the agent to read local context files (.agents/product-marketing-context.md or .claude/product-marketing-context.md) to personalize its advice. This represents a potential surface for indirect prompt injection if an attacker controls those local files. However, the risk is negligible as the skill lacks high-privilege capabilities.
  • Ingestion points: SKILL.md references reading .agents/product-marketing-context.md and .claude/product-marketing-context.md.
  • Boundary markers: None present in the instructions.
  • Capability inventory: The skill is restricted to providing text-based recommendations and copy analysis; no shell execution, file-writing, or network operations are requested or used.
  • Sanitization: No explicit sanitization of the context file content is defined.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 16, 2026, 12:10 PM
Security Audit — agent-trust-hub — paywall-upgrade-cro