payment-funnel-analysis

Pass

Audited by Gen Agent Trust Hub on Aug 24, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is entirely focused on its declared role as a payment funnel expert. It provides comprehensive templates for general, first-purchase, and gacha funnels, as well as a multi-stage workflow that guides the user through data-driven optimization. The instructions are professional and lack any deceptive or malicious content.
  • [DATA_EXPOSURE_AND_EXFILTRATION]: The skill interacts with the ThinkingData analytics environment via the ae-cli tool. All data retrieval and creation operations (such as list-projects, report-data run, and dashboard create) are confined to this specialized toolset within the intended project context. There are no hardcoded secrets, and no evidence of attempts to exfiltrate data to non-whitelisted or external domains.
  • [REMOTE_CODE_EXECUTION]: No remote code execution patterns were detected. The skill uses structured JSON for ad-hoc funnel definitions, but these are passed to the ae-cli tool for compilation and execution against the analytics cluster, which is standard functionality for this domain. The skill does not attempt to download or execute external scripts or packages.
  • [PROMPT_INJECTION]: The skill contains a 'Language Policy' labeled as CRITICAL, but this is a benign instruction to match the user's input language. There are no instructions to bypass safety filters, override core system rules, or reveal internal system prompts.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests data from external sources such as analytics reports and dashboards. While this represents a potential attack surface, the risk is handled through structured AI-facing definitions and compiler validation steps. \n
  • Ingestion points: Data returned from analysis report-data run and analysis adhoc run commands. \n
  • Boundary markers: The skill instructs the agent to check compile resolution and warnings before interpreting results. \n
  • Capability inventory: The skill can create reports and dashboards via ae-cli tools after verification. \n
  • Sanitization: The skill relies on structured metadata resolution and compiler-assisted query building to ensure inputs are interpreted as data rather than instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 24, 2026, 10:17 AM
Security Audit — agent-trust-hub — payment-funnel-analysis