cro-advisor
Pass
Audited by Gen Agent Trust Hub on Apr 5, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill provides instructions for the agent to execute local Python tools such as scripts/revenue_forecast_model.py and scripts/churn_analyzer.py to process business metrics.
- [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface as it processes data from user queries and external context files. 1. Ingestion points: User-provided revenue data and company-context.md. 2. Boundary markers: No specific delimiters are defined in the instructions to isolate untrusted data. 3. Capability inventory: Shell execution of internal scripts and multi-agent task delegation. 4. Sanitization: No input validation or filtering logic is specified.
- [SAFE]: The overall behavior of the skill is consistent with its stated purpose, with no evidence of obfuscation or malicious intent.
Audit Metadata