referral-program

Pass

Audited by Gen Agent Trust Hub on Apr 5, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [SAFE]: The skill follows standard business consulting patterns for growth engineering. All instructions and references are focused on marketing strategy and program mechanics.
  • [COMMAND_EXECUTION]: The skill references a local Python script, scripts/referral_roi_calculator.py, which is used to model financial metrics such as ROI, Lifetime Value (LTV), and Customer Acquisition Cost (CAC). This script is a functional component of the skill intended for business analysis.
  • [DATA_EXFILTRATION]: The agent is instructed to request business-specific context, including customer data and financial metrics. This information is required for the skill's purpose and does not involve exfiltration to external domains.
  • [PROMPT_INJECTION]: The skill demonstrates an attack surface for indirect prompt injection. 1. Ingestion points: Untrusted user-supplied marketing context and product data (SKILL.md). 2. Boundary markers: Not present in the prompt instructions. 3. Capability inventory: Execution of local calculation script and generation of program artifacts. 4. Sanitization: No specific input validation or sanitization is mentioned.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 5, 2026, 08:06 PM
Security Audit — agent-trust-hub — referral-program