form-cro
Pass
Audited by Gen Agent Trust Hub on Sep 4, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill is a standard utility for marketing optimization. It does not contain any remote dependencies, obfuscation, or high-risk command execution patterns.
- [INDIRECT_PROMPT_INJECTION]: The skill processes user-provided HTML files via a Python script. Ingestion Point: scripts/form_field_analyzer.py reads file content based on user-provided arguments. Boundary Markers: None explicitly defined in the script's output to the agent. Capability Inventory: The skill only generates text-based marketing advice and reports; it lacks capabilities for network access, file writing, or subprocess execution. Sanitization: The script uses a standard HTML parser to extract specific attributes but does not perform safety-oriented sanitization of the input data. The risk is considered negligible due to the absence of exploitable capabilities.
Audit Metadata