onboarding-cro
Pass
Audited by Gen Agent Trust Hub on Sep 5, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONNO_CODE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to process user-supplied product descriptions, activation metrics, and onboarding flow details to generate audits and recommendations. While there are no explicit boundary markers or instructions to treat this data as untrusted, the skill lacks any executable capabilities—such as file writing, network requests, or system command execution—that could be exploited through prompt injection. The risk is limited to influencing the agent's textual output.
- [SAFE]: The skill consists entirely of natural language instructions and domain-specific documentation for Conversion Rate Optimization (CRO). It does not include any scripts, external dependencies, or executable code blocks. All referenced files are local markdown documents used for context.
Audit Metadata