aarrr-metrics

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFENO_CODE
Full Analysis
  • [SAFE]: The skill provides structural guidance for growth metric analysis. It contains no executable code, scripts, or network operations.
  • [NO_CODE]: The skill consists entirely of markdown documentation, instructions, and examples. It does not include any scripts (Python, Node.js, Shell) or configuration files that could execute logic.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process user-provided business metrics to generate dashboards. While this constitutes an ingestion surface, the skill lacks high-privilege capabilities such as file writes or network access, making the risk of indirect injection exploitation negligible.
  • [METADATA_POISONING]: Metadata correctly identifies the author and purpose without deceptive intent. The mcp-server reference matches the author's namespace (@clawfu).
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 08:26 PM
Security Audit — agent-trust-hub — aarrr-metrics