revenue-centric-design
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill implements a robust safety mechanism via
scripts/check_usage_boundary.pyto ensure compliance with its license terms, which prohibit its use in gambling, betting, or casino-related projects. This script uses non-sensitive file system access to scan project files for specific keywords and exits with a specific code to block agent actions in unauthorized contexts. - [SAFE]: The
scripts/revenue_math.pyfile provides utility functions for business calculations such as A/B testing sample sizes, Churn-to-LTV impact, and Customer Acquisition Cost (CAC). The script uses standard libraries and performs purely mathematical operations. - [SAFE]: The skill uses platform-standard hooks to automate its safety boundary checks. The commands executed (
python3 <skill_dir>/scripts/check_usage_boundary.py) are static and do not interpolate untrusted user input into shell commands, preventing command injection vulnerabilities. - [INDIRECT_PROMPT_INJECTION]: The skill's boundary check script ingests untrusted project data (READMEs, package.json, etc.) to scan for keywords.
- Ingestion points:
scripts/check_usage_boundary.pyreads project files and stdin content during hook execution. - Boundary markers: The script itself acts as a boundary enforcement tool, checking for policy violations.
- Capability inventory: The skill has capabilities for file reads, business math, and exiting with codes to block execution. It does not possess network or arbitrary code execution capabilities.
- Sanitization: The script uses regular expressions with strict word boundaries to identify keywords without executing the ingested content. The potential risk is limited to a denial-of-service (blocking the skill's use) if an attacker can trigger a false positive, rather than a security compromise.
Audit Metadata