paywall-upgrade-cro

Pass

Audited by Gen Agent Trust Hub on Aug 27, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes potentially untrusted data from external sources and user context, establishing a surface for indirect prompt injection.
  • Ingestion points: User-provided product models, journey descriptions, and external web content retrieved via tools like BrowserOS.
  • Boundary markers: The instructions do not define explicit delimiters or boundary markers to isolate ingested content.
  • Capability inventory: The agent is authorized to interact with shell environments (via ExecutionProxy), update issue trackers (Linear), and write to persistent documentation (Obsidian).
  • Sanitization: The skill contains a positive security protocol requiring the agent to treat external inputs as hostile and redact PII or secrets before context sharing.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 27, 2026, 07:36 AM
Security Audit — agent-trust-hub — paywall-upgrade-cro