revenue-centric-design

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill implements a robust safety mechanism via scripts/check_usage_boundary.py to ensure compliance with its license terms, which prohibit its use in gambling, betting, or casino-related projects. This script uses non-sensitive file system access to scan project files for specific keywords and exits with a specific code to block agent actions in unauthorized contexts.
  • [SAFE]: The scripts/revenue_math.py file provides utility functions for business calculations such as A/B testing sample sizes, Churn-to-LTV impact, and Customer Acquisition Cost (CAC). The script uses standard libraries and performs purely mathematical operations.
  • [SAFE]: The skill uses platform-standard hooks to automate its safety boundary checks. The commands executed (python3 <skill_dir>/scripts/check_usage_boundary.py) are static and do not interpolate untrusted user input into shell commands, preventing command injection vulnerabilities.
  • [INDIRECT_PROMPT_INJECTION]: The skill's boundary check script ingests untrusted project data (READMEs, package.json, etc.) to scan for keywords.
  • Ingestion points: scripts/check_usage_boundary.py reads project files and stdin content during hook execution.
  • Boundary markers: The script itself acts as a boundary enforcement tool, checking for policy violations.
  • Capability inventory: The skill has capabilities for file reads, business math, and exiting with codes to block execution. It does not possess network or arbitrary code execution capabilities.
  • Sanitization: The script uses regular expressions with strict word boundaries to identify keywords without executing the ingested content. The potential risk is limited to a denial-of-service (blocking the skill's use) if an attacker can trigger a false positive, rather than a security compromise.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 08:20 AM
Security Audit — agent-trust-hub — revenue-centric-design