form-cro

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFENO_CODE
Full Analysis
  • [SAFE]: The skill is composed entirely of markdown-based instructions and scoring frameworks. It contains no scripts, shell commands, or executable code blocks.
  • [SAFE]: No external downloads, package dependencies, or remote code execution patterns were detected. The skill does not perform network operations.
  • [INDIRECT_PROMPT_INJECTION]: The skill analyzes external data (user-provided form structures and performance metrics), creating a potential surface for indirect prompt injection. However, the risk is negligible as the skill lacks any dangerous capabilities to exploit.
  • Ingestion points: User-supplied form context, business descriptions, and performance metrics (defined in Phase 1).
  • Boundary markers: None identified in the prompt templates.
  • Capability inventory: No subprocess execution, file system modification, or network operations are present in the skill.
  • Sanitization: None identified; the skill processes input as plain text for diagnostic purposes.
  • [NO_CODE]: The skill operates as a purely instructional guide for the agent to follow when performing audits, with no technical execution component.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 07:18 AM
Security Audit — agent-trust-hub — form-cro