page-cro

Pass

Audited by Gen Agent Trust Hub on Apr 5, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill is susceptible to Indirect Prompt Injection (Category 8) as it processes untrusted external data entered via user-provided URLs, copy, and the .claude/product-marketing-context.md file.
  • Ingestion points: Data enters through page URLs, marketing copy (README.md, SKILL.md), and the .claude/product-marketing-context.md context file (SKILL.md).
  • Boundary markers: Absent; instructions do not provide delimiters (like XML tags) or directives for the agent to ignore instructions embedded within the analyzed content.
  • Capability inventory: No dangerous capabilities such as shell command execution, file-writing, or network-writing tools are identified in the provided skill definition.
  • Sanitization: Absent; the skill does not specify any input validation, escaping, or filtering for the external content before processing.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 5, 2026, 08:06 PM
Security Audit — agent-trust-hub — page-cro