signup-flow-cro
Pass
Audited by Gen Agent Trust Hub on Feb 21, 2026
Risk Level: SAFE
Full Analysis
- [SAFE] (SAFE): No malicious code or patterns detected.
- [Prompt Injection] (SAFE): No attempts to bypass safety filters or override system instructions were found. The 'expert' persona is limited to the conversion rate optimization (CRO) domain.
- [Data Exposure & Exfiltration] (SAFE): No credentials, sensitive file paths, or network exfiltration patterns identified. The reference to .claude/product-marketing-context.md is a standard practice for context-aware agents to access local project metadata.
- [External Downloads & RCE] (SAFE): No external dependencies, package installations, or remote script executions detected.
- [Indirect Prompt Injection] (LOW): The skill checks for a local context file (.claude/product-marketing-context.md). While this is an ingestion point, it is a local file intended for context and does not constitute a high-risk surface for untrusted external data in this static context.
Audit Metadata