cro
Pass
Audited by Gen Agent Trust Hub on Aug 28, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill directs the agent to analyze external and potentially untrusted data sources to improve marketing conversion, which creates a surface where malicious instructions could be embedded in the audited content to influence agent behavior. \n
- Ingestion points: The workflow in 'references/page-and-form-workflow.md' involves inspecting traffic data, recordings, heatmaps, polls, interviews, and sales tickets. \n
- Boundary markers: The instructions do not define specific delimiters or guidelines to ignore embedded instructions within the processed external data. \n
- Capability inventory: The skill is purely instructional and does not include executable scripts or specific tool-use definitions that could be leveraged for privilege escalation or exfiltration. \n
- Sanitization: No sanitization or filtering of external content is specified in the skill's workflow.
Audit Metadata