cro

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to process external content such as landing pages and user-provided URLs for the purpose of conversion rate analysis. This creates a surface for indirect prompt injection if the external content contains malicious instructions intended for the agent. However, this functionality is essential to the skill's primary purpose, and the skill lacks any high-risk capabilities (like shell execution or network exfiltration) that would make such an injection dangerous.
  • Ingestion points: User-provided URLs and page content as described in SKILL.md.
  • Boundary markers: Absent; the instructions do not define strict delimiters or ignore-instructions for the external content being analyzed.
  • Capability inventory: The skill does not include any high-risk tools, scripts, or system-level execution patterns; it focuses solely on producing text-based analytical recommendations.
  • Sanitization: Absent; the skill relies on the underlying LLM's standard safety guardrails for processing external content.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 10:13 AM
Security Audit — agent-trust-hub — cro