ab-test-setup

Pass

Audited by Gen Agent Trust Hub on May 14, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill is entirely instructional, offering best practices and documentation templates for experimentation and CRO. No code or scripts are included in the skill files.
  • [EXTERNAL_DOWNLOADS]: The skill provides links to well-known third-party A/B testing calculators such as Evan Miller's calculator, Optimizely, and VWO. These resources are industry standard and are used purely for statistical calculations.
  • [PROMPT_INJECTION]: The skill instructs the agent to read a local file, .claude/product-marketing-context.md, to gain context before assisting the user. While this represents a surface for indirect prompt injection if the file were to contain untrusted instructions, the skill does not possess any exploitable capabilities (no network access, file writing, or subprocess execution tools), making the risk negligible. (Ingestion points: .claude/product-marketing-context.md in SKILL.md; Boundary markers: Absent; Capability inventory: None; Sanitization: Absent).
Audit Metadata
Risk Level
SAFE
Analyzed
May 14, 2026, 05:59 AM
Security Audit — agent-trust-hub — ab-test-setup