cro-methodology
Pass
Audited by Gen Agent Trust Hub on Jun 21, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: Extensive review of all seven files confirms that the skill is purely documentation-based. There are no executable scripts, system commands, or network-enabled tools defined in the skill structure.- [PROMPT_INJECTION]: The skill establishes a workflow for analyzing external websites and customer feedback (as seen in SKILL.md and RESEARCH.md), which constitutes a potential ingestion surface for untrusted data. 1. Ingestion points: Website landing pages, customer support logs, and reviews provided by the user for auditing. 2. Boundary markers: Not present in the instructional text. 3. Capability inventory: None; the skill contains no scripts, tools, or subprocess calls. 4. Sanitization: Not specified. This vulnerability surface is considered safe because the skill does not provide the agent with any automated capabilities to act on or execute data extracted from these sources.
Audit Metadata