conversion-flow-cro

Pass

Audited by Gen Agent Trust Hub on Jul 14, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: No malicious injection patterns, bypass attempts, or behavioral overrides were detected in the instructions.
  • [DATA_EXFILTRATION]: The skill does not access sensitive local file paths (like credentials or SSH keys) and contains no network operations targeting external domains.
  • [REMOTE_CODE_EXECUTION]: There are no commands for downloading, piping, or executing remote scripts or packages.
  • [OBFUSCATION]: No encoded strings (Base64/hex), zero-width characters, or homoglyph substitutions were found in the skill files.
  • [DYNAMIC_EXECUTION]: The skill does not generate or execute code at runtime. It relies entirely on text-based analysis and reporting.
  • [INDIRECT_PROMPT_INJECTION]: While the skill ingests external data (codebase, URLs, screenshots) for analysis, it lacks the dangerous capabilities (like file writing or command execution) necessary to form an exploit chain.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 14, 2026, 02:05 PM
Security Audit — agent-trust-hub — conversion-flow-cro