form-cro
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFENO_CODE
Full Analysis
- [SAFE]: The skill is composed entirely of markdown-based instructions and scoring frameworks. It contains no scripts, shell commands, or executable code blocks.
- [SAFE]: No external downloads, package dependencies, or remote code execution patterns were detected. The skill does not perform network operations.
- [INDIRECT_PROMPT_INJECTION]: The skill analyzes external data (user-provided form structures and performance metrics), creating a potential surface for indirect prompt injection. However, the risk is negligible as the skill lacks any dangerous capabilities to exploit.
- Ingestion points: User-supplied form context, business descriptions, and performance metrics (defined in Phase 1).
- Boundary markers: None identified in the prompt templates.
- Capability inventory: No subprocess execution, file system modification, or network operations are present in the skill.
- Sanitization: None identified; the skill processes input as plain text for diagnostic purposes.
- [NO_CODE]: The skill operates as a purely instructional guide for the agent to follow when performing audits, with no technical execution component.
Audit Metadata