fluentcrm-funnel-action

Pass

Audited by Gen Agent Trust Hub on Sep 9, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides legitimate technical documentation and code examples for extending the FluentCRM WordPress plugin. All implementation details align with the stated purpose of the skill.
  • [DATA_EXPOSURE_AND_EXFILTRATION]: No hardcoded credentials, sensitive file path access, or unauthorized network operations were detected. Code examples use appropriate plugin-specific APIs and standard WordPress patterns.
  • [REMOTE_CODE_EXECUTION]: The skill does not contain patterns for downloading or executing remote scripts. It provides static PHP templates for developers to implement locally.
  • [OBFUSCATION]: No obfuscation techniques such as Base64 encoding of commands, zero-width characters, or homoglyph attacks were found. The use of accented characters in the author's name is legitimate and non-malicious.
  • [INDIRECT_PROMPT_INJECTION]: The skill handles data from external sources (FluentCRM subscriber data) but includes safety measures in its examples, such as integer casting and precondition validation, to prevent common injection vulnerabilities in the resulting code.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 9, 2026, 07:05 PM
Security Audit — agent-trust-hub — fluentcrm-funnel-action