cpo-advisor
Pass
Audited by Gen Agent Trust Hub on Sep 4, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill provides strategic leadership guidance and local analytical tools. No malicious patterns or security risks were identified across the documentation or Python scripts.
- [INDIRECT_PROMPT_INJECTION]: The skill includes a surface for processing untrusted data via JSON inputs to scripts/pmf_scorer.py and scripts/portfolio_analyzer.py. However, the capability inventory reveals no subprocess calls, exec/eval, file-write, or network operations, ensuring that data ingestion cannot be exploited for malicious actions.
- [DATA_EXFILTRATION]: No network operations or access to sensitive environment files (such as SSH keys or credentials) were detected. The scripts function purely as local calculators.
- [OBFUSCATION]: No evidence of encoding, zero-width characters, homoglyphs, or other obfuscation techniques was found in the skill content or associated scripts.
Audit Metadata