conversion-psychology

Pass

Audited by Gen Agent Trust Hub on Jul 24, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill uses local reference files for detailed guidelines and contains no hardcoded credentials or unauthorized remote execution patterns. References to external services like Notion or LinkedIn are used for illustrative purposes and do not involve active data connections.
  • [PROMPT_INJECTION]: The skill implements a research protocol that ingests external data from web search results to inform design decisions and code generation, creating a surface for indirect prompt injection.
  • Ingestion points: Web search results synthesized during Phase 1 (SKILL.md).
  • Boundary markers: No specific delimiters or safety instructions are provided to the agent to distinguish external research data from its core instructions.
  • Capability inventory: The agent is instructed to generate UI components and code snippets (React/TS/CSS) based on the synthesized research.
  • Sanitization: The instructions do not define validation or sanitization procedures for content retrieved from search queries before it influences the generated output.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 24, 2026, 12:50 PM
Security Audit — agent-trust-hub — conversion-psychology