cpo-advisor
Pass
Audited by Gen Agent Trust Hub on Jun 17, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: Detailed analysis of the skill instructions and Python scripts revealed no malicious intent, obfuscation, or safety bypass attempts.
- [COMMAND_EXECUTION]: The skill uses local Python scripts (
pmf_scorer.py,portfolio_analyzer.py) for analytical processing. These scripts are restricted to standard libraries (json,sys,argparse,math), contain no dangerous execution sinks likeeval()orexec(), and do not make system or network calls. They operate purely on user-provided data inputs. - [DATA_EXFILTRATION]: No network capabilities are requested or used within the skill. All data processing and report generation occur within the local environment without external communication.
- [PROMPT_INJECTION]: The skill's instructions are well-structured for product leadership tasks and do not contain patterns intended to manipulate the agent's core safety guidelines or extract system prompts.
Audit Metadata