cpo-advisor

Pass

Audited by Gen Agent Trust Hub on Sep 4, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides strategic leadership guidance and local analytical tools. No malicious patterns or security risks were identified across the documentation or Python scripts.
  • [INDIRECT_PROMPT_INJECTION]: The skill includes a surface for processing untrusted data via JSON inputs to scripts/pmf_scorer.py and scripts/portfolio_analyzer.py. However, the capability inventory reveals no subprocess calls, exec/eval, file-write, or network operations, ensuring that data ingestion cannot be exploited for malicious actions.
  • [DATA_EXFILTRATION]: No network operations or access to sensitive environment files (such as SSH keys or credentials) were detected. The scripts function purely as local calculators.
  • [OBFUSCATION]: No evidence of encoding, zero-width characters, homoglyphs, or other obfuscation techniques was found in the skill content or associated scripts.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 4, 2026, 12:32 PM
Security Audit — agent-trust-hub — cpo-advisor