aarrr-metrics
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFENO_CODE
Full Analysis
- [SAFE]: The skill provides structural guidance for growth metric analysis. It contains no executable code, scripts, or network operations.
- [NO_CODE]: The skill consists entirely of markdown documentation, instructions, and examples. It does not include any scripts (Python, Node.js, Shell) or configuration files that could execute logic.
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process user-provided business metrics to generate dashboards. While this constitutes an ingestion surface, the skill lacks high-privilege capabilities such as file writes or network access, making the risk of indirect injection exploitation negligible.
- [METADATA_POISONING]: Metadata correctly identifies the author and purpose without deceptive intent. The mcp-server reference matches the author's namespace (@clawfu).
Audit Metadata