pricing-strategy-skill
Pass
Audited by Gen Agent Trust Hub on Aug 4, 2026
Risk Level: SAFENO_CODE
Full Analysis
- [SAFE]: The skill consists exclusively of markdown instructions and metadata. No executable scripts, binaries, or configuration files that could carry active payloads were found.
- [NO_CODE]: There are no program files (Python, JavaScript, shell scripts) included in the skill, significantly reducing the attack surface.
- [DATA_EXPOSURE]: The skill's 'Workflow: Bifurcación de Diagnóstico' instructs the agent to scan the local workspace for existing files and folder structures (e.g., package.json, src/). This is a benign diagnostic activity intended to identify the project's technical stack and does not involve sending data to external servers.
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze untrusted project data (existing code). While this creates a theoretical surface for indirect prompt injection where malicious comments in code could influence the agent, the skill's capabilities are limited to generating markdown documentation within the same workspace, and no critical capability abuse was detected.
Audit Metadata