cro-methodology

Pass

Audited by Gen Agent Trust Hub on Jul 10, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill consists of informational markdown files that provide guidance on business optimization. It contains no executable scripts, system commands, or network operations that could pose a security risk.
  • [PROMPT_INJECTION]: The skill instructions involve analyzing untrusted external data such as customer reviews, survey responses, and chat logs as part of the research process (referenced in RESEARCH.md and OBJECTIONS.md). This creates a surface for indirect prompt injection. However, because the skill is limited to providing advice and does not include capabilities for automated actions or high-privilege tool use, the risk is minimal. * Ingestion points: Customer reviews, surveys, and support logs mentioned in RESEARCH.md and OBJECTIONS.md. * Boundary markers: None specified. * Capability inventory: None (informational methodology only). * Sanitization: None described.
  • [DATA_EXFILTRATION]: No data exfiltration patterns were found. The only external link is to an official book listing on Amazon, which is a well-known service.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 10, 2026, 12:22 PM
Security Audit — agent-trust-hub — cro-methodology