popup-cro

Pass

Audited by Gen Agent Trust Hub on Apr 29, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is entirely instructional and does not execute shell commands, perform network requests, or include any scripts.
  • [DATA_EXPOSURE]: The skill attempts to read context from .agents/product-marketing-context.md if it exists. This is a standard practice for agent personalization and does not involve accessing sensitive system files or credentials.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests data from local context files which could theoretically contain malicious instructions. However, the risk is negligible as the skill only outputs marketing advice and text copy, with no dangerous capabilities (like command execution or file writing) to exploit.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 29, 2026, 11:09 PM
Security Audit — agent-trust-hub — popup-cro