signup-flow-cro
Pass
Audited by Gen Agent Trust Hub on Sep 5, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill consists of standard markdown instructions and documentation for performing conversion rate optimization (CRO) audits. No malicious patterns, obfuscation, or unauthorized data access were found.
- [INDIRECT_PROMPT_INJECTION]: The skill identifies a potential data ingestion point by instructing the agent to read context from
.agents/product-marketing-context.md. While this is a data surface, the risk is negligible as the skill lacks exploitable capabilities. - Ingestion points:
.agents/product-marketing-context.md(and older.claude/variant) referenced inSKILL.md. - Boundary markers: None; the skill does not specify markers to separate ingested context from instructions.
- Capability inventory: The skill is limited to providing text-based audit findings and recommendations; it does not request network access, file-writing, or command execution tools.
- Sanitization: None; the agent is instructed to read the file contents directly.
Audit Metadata