ab-test-setup

Pass

Audited by Gen Agent Trust Hub on Feb 17, 2026

Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
  • Indirect Prompt Injection (LOW): The skill ingests data from .claude/product-marketing-context.md. Evidence Chain: 1. Ingestion points: .claude/product-marketing-context.md. 2. Boundary markers: Absent; there are no delimiters or instructions to ignore embedded commands. 3. Capability inventory: No subprocess calls, network operations, or file-write capabilities are defined across any of the files. 4. Sanitization: Absent.
  • Data Exposure & Exfiltration (SAFE): No sensitive file paths (e.g., .ssh, .aws) or hardcoded credentials were found. External links point to reputable third-party A/B testing calculators.
  • Remote Code Execution (SAFE): No scripts are provided with the skill, and there are no instructions to download or execute external code.
Audit Metadata
Risk Level
SAFE
Analyzed
Feb 17, 2026, 06:29 PM