paywall-upgrade-cro
Pass
Audited by Gen Agent Trust Hub on Aug 27, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes potentially untrusted data from external sources and user context, establishing a surface for indirect prompt injection.
- Ingestion points: User-provided product models, journey descriptions, and external web content retrieved via tools like BrowserOS.
- Boundary markers: The instructions do not define explicit delimiters or boundary markers to isolate ingested content.
- Capability inventory: The agent is authorized to interact with shell environments (via ExecutionProxy), update issue trackers (Linear), and write to persistent documentation (Obsidian).
- Sanitization: The skill contains a positive security protocol requiring the agent to treat external inputs as hostile and redact PII or secrets before context sharing.
Audit Metadata