paywall-upgrade-cro
Pass
Audited by Gen Agent Trust Hub on Sep 4, 2026
Risk Level: SAFENO_CODE
Full Analysis
- [NO_CODE]: The skill is composed entirely of markdown instructions and templates. It does not include or invoke any scripts, binaries, or command-line tools.
- [SAFE]: No obfuscation, hardcoded credentials, or persistence mechanisms were detected. The skill's instructions are consistent with its stated purpose of conversion rate optimization (CRO).
- [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to read product marketing context from a local file if it exists, creating a surface for indirect instructions.
- Ingestion points:
.claude/product-marketing-context.mdin the local environment. - Boundary markers: Absent; the skill does not instruct the agent to distinguish between the file's data and its instructions.
- Capability inventory: The skill does not request or use any sensitive tools, subprocess execution, or network capabilities, which mitigates the risk of an injection payload performing harmful actions.
- Sanitization: Not present.
Audit Metadata