paywalls
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to read context from local files such as
.agents/product-marketing.md,.claude/product-marketing.md, orproduct-marketing-context.mdto provide personalized recommendations. - Ingestion points: Reads project-specific marketing context from specified markdown files in the local environment (SKILL.md).
- Boundary markers: The instructions do not specify the use of delimiters or "ignore embedded instructions" warnings for the ingested content.
- Capability inventory: The skill provides informational recommendations and does not invoke subprocesses, network operations, or file-writing tools.
- Sanitization: There are no explicit instructions to sanitize or validate the content of the marketing files before processing.
- [SAFE]: No malicious patterns such as credential theft, remote code execution, or unauthorized command execution were identified. The skill's behavior aligns with its stated purpose of providing conversion rate optimization advice for paywalls.
Audit Metadata