popup-cro

Pass

Audited by Gen Agent Trust Hub on Sep 5, 2026

Risk Level: SAFENO_CODE
Full Analysis
  • [SAFE]: The skill consists entirely of instructional markdown and does not include any scripts, commands, or executable code.
  • [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to read context from local files like .agents/product-marketing-context.md. While this represents a data ingestion point for untrusted content from a repository, the skill lacks the capabilities (network access, file writing, or command execution) required to weaponize any potential injection.
  • [DATA_EXPOSURE_&_EXFILTRATION]: No sensitive file paths or network operations were detected. The file access is restricted to project-specific marketing context files.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 5, 2026, 02:58 PM
Security Audit — agent-trust-hub — popup-cro