Skip to content
Report library
Purpose / Other

Cro Skill Security Audit

What the author says it does (original text)

When the user wants to optimize, improve, or increase conversions on any marketing page or form — including homepage, landing pages, pricing pages, feature pages, lead capture forms, or contact forms. Also use when the user says 'CRO,' 'conversion rate optimization,' 'this page isn't converting,' 'improve conversions,' 'why isn't this page working,' 'my landing page sucks,' 'form abandonment,' 'no

Independent security check

Security risks found

Files checked
4
Risks found
3
Could it run dangerous commands?Looks for programs run straight after downloading, remote control of your computer, and hidden commands.No risks found
Could it expose your files or keys?Looks for uploads of files containing passwords or keys, and keys written directly in the code.Risks found: 1
Medium risk

Recommendations may expand visitor tracking and send form-derived data to enrichment services

Source references: 4
What we found

The guidance suggests field-level behavioral tracking, personalization based on visitor data, and post-submission enrichment using services such as Clearbit. It does not require prior decisions about data minimization, consent, retention, or third-party transfers.

Why this matters

Implementation could increase collection of personal and behavioral data and disclose email-derived company information to a third party, increasing privacy, compliance, and breach exposure.

These are recommendations, not automatically executing code, but they expressly propose field-level interaction tracking, visitor-segment personalization, and inferring or enriching information through services such as Clearbit. If implemented, this could expand behavioral monitoring or third-party transfer and inference of personal or company data, without accompanying requirements for consent, minimization, retention, or vendor review. Users can require minimal event collection, prohibit capturing sensitive field contents, and mandate privacy review before enrichment or personalization.

references/form.md:294In the instructionsOpen original file
### What to Track- Form views- First field focus- Each field completion- Errors by field- Submit attempts- Successful submissions
Show 3 other places
references/form.md:79In the instructionsOpen original file
### Company/Organization- Auto-suggest for faster entry- Enrichment after submission (Clearbit, etc.)- Consider inferring from email domain
references/experiments.md:234In the instructionsOpen original file
|------|------------|| Chat widget | Impact on conversions || Cookie consent UX | Minimize friction || Page load speed | Performance vs. features || Mobile experience | Responsive optimization || Accessibility | Impact on conversion || Personalization | Dynamic content by segment |
references/experiments.md:232In the instructionsOpen original file
| Test | Hypothesis ||------|------------|| Chat widget | Impact on conversions || Cookie consent UX | Minimize friction || Page load speed | Performance vs. features || Mobile experience | Responsive optimization || Accessibility | Impact on conversion || Personalization | Dynamic content by segment |
Could it delete files or keep running?Looks for broad file deletion, disk overwrites, and programs set to start automatically.No risks found
Could it bypass safety checks?Looks for skipped website security checks, excessive file access, or actions that skip your approval.No risks found
Could it mislead the AI or hide text?Checks the skill instructions for requests to ignore you, influence the report, or hide text in invisible characters.Risks found: 1
Medium risk

Project marketing files can introduce prompt injection into the agent context

Source references: 2
What we found

The Skill tells the agent to read fixed project files and “use that context,” but does not say to treat their contents only as data, ignore commands, or guard against prompt injection. Anyone able to alter the repository could place unrelated instructions in those files.

Why this matters

Embedded instructions could manipulate the audit recommendations. In an environment where the agent also has file, network, or account tools, they could also induce attempts at actions outside page analysis.

The live instructions require the agent to read fixed marketing files from the repository and directly “use that context,” without saying their contents must be treated only as data rather than instructions. If a repository contributor can modify those files, embedded prompts could steer the agent beyond the requested CRO analysis. This depends on the files existing and what they contain; the citation does not show that injection occurred. Users can ask for an explicit untrusted-data boundary and restricted reading scope.

SKILL.md:14In the instructionsOpen original file
**Check for product marketing context first:**If `.agents/product-marketing.md` exists (or `.claude/product-marketing.md`, or the legacy `product-marketing-context.md` filename, in older setups), read it before asking questions. Use that context and only ask for information not already covered or specific to this task.
Show 1 other places
references/form.md:7In the instructionsOpen original file
**Check for product marketing context first:**If `.agents/product-marketing.md` exists (or `.claude/product-marketing.md` in older setups), read it before asking questions. Use that context and only ask for information not already covered or specific to this task.
Could it change links or payment recipients without asking?Looks for forced referral or payment changes combined with instructions to hide the change.Risks found: 1
Medium risk

Conversion advice can produce unverified privacy promises, social proof, or plan labels

Source references: 6
What we found

The guidance offers promises such as “We'll never share your info” and “We won't share your number,” and suggests customer counts, badges, reviews, and “Most Popular” plan labels without requiring proof that they match actual data practices or purchasing behavior.

Why this matters

If inaccurate claims are published, customers may submit data or select plans based on false information, exposing the user to complaints, refunds, regulatory consequences, and reputational harm.

The guidance offers absolute privacy promises such as “We'll never share your info” and “We won't share your number,” while also recommending customer logos, reviews, numerical claims, and a recommended-plan marker without requiring verification of actual data handling, customer permission, review provenance, or purchase distribution. If copied directly, visitors could submit data or buy based on unsupported claims. Users can require privacy, legal, and evidence-owner approval before publication and ensure plan labels are clearly editorial or supported by real usage data.

references/form.md:220In the instructionsOpen original file
### Near the Form- Privacy statement: "We'll never share your info"- Security badges if collecting sensitive data- Testimonial or social proof- Expected response time### Reducing Perceived Effort- "Takes 30 seconds"- Field count indicator- Remove visual clutter- Generous white space### Addressing Objections- "No spam, unsubscribe anytime"- "We won't share your number"- "No credit card required"
Show 5 other places
references/form.md:232In the instructionsOpen original file
### Addressing Objections- "No spam, unsubscribe anytime"- "We won't share your number"- "No credit card required"
SKILL.md:48In the instructionsOpen original file
**Strong headline patterns:**- Outcome-focused: "Get [desired outcome] without [pain point]"- Specificity: Include numbers, timeframes, or concrete details- Social proof: "Join 10,000+ teams who..."
references/experiments.md:68In the instructionsOpen original file
|------|------------|| Annual vs. monthly display | Highlight savings or simplify || Price points | $99 vs. $100 vs. $97 psychology || "Most Popular" badge | Highlight target plan || Number of tiers | 3 vs. 4 vs. 2 visible options || Price anchoring | Order plans to anchor expectations || Custom enterprise tier | Show vs. "Contact Sales" |
SKILL.md:74In the instructionsOpen original file
### 5. Trust Signals and Social Proof**Types to look for:**- Customer logos (especially recognizable ones)- Testimonials (specific, attributed, with photos)- Case study snippets with real numbers- Review scores and counts- Security badges (where relevant)**Placement:** Near CTAs and after benefit claims
SKILL.md:137In the instructionsOpen original file
### Pricing Page CRO- Clear plan comparison- Recommended plan indication- Address "which plan is right for me?" anxiety

Inside this skill

8 instruction sections

The Skill primarily analyzes marketing pages or forms and produces quick wins, higher-impact changes, A/B tests, and copy suggestions. The provided source contains no scripts, installation steps, or instructions to directly modify a page.

View source
SKILL.md:10In the instructionsOpen original file
You are a conversion rate optimization expert. Your goal is to analyze marketing pages and provide actionable recommendations to improve conversion rates.
SKILL.md:109In the instructionsOpen original file
Structure your recommendations as:### Quick Wins (Implement Now)Easy changes with likely immediate impact.### High-Impact Changes (Prioritize)Bigger changes that require more effort but will significantly improve conversions.### Test IdeasHypotheses worth A/B testing rather than assuming.### Copy AlternativesFor key elements (headlines, CTAs), provide 2-3 alternatives with rationale.

At runtime, it first checks for and reads a product-marketing context file in the project, then uses that content to avoid repeated questions.

View source
SKILL.md:14In the instructionsOpen original file
**Check for product marketing context first:**If `.agents/product-marketing.md` exists (or `.claude/product-marketing.md`, or the legacy `product-marketing-context.md` filename, in older setups), read it before asking questions. Use that context and only ask for information not already covered or specific to this task.

The Skill recommends collecting granular form behavior metrics—including views, field interactions, errors, and submissions—and may suggest enrichment or personalization.

View source
references/form.md:294In the instructionsOpen original file
### What to Track- Form views- First field focus- Each field completion- Errors by field- Submit attempts- Successful submissions
references/form.md:79In the instructionsOpen original file
### Company/Organization- Auto-suggest for faster entry- Enrichment after submission (Clearbit, etc.)- Consider inferring from email domain
Start here · InstructionsSKILL.md
cro
Lines connect the instruction file to its sections, not an observed execution order. Select a section to read the source.

File reference map

References: 2
Files making referencesReferenced content
Lines show actual file references, not execution order. Select a node to highlight its connections and inspect the files and source locations. Dashed lines include files that still need locating.
Files and check records4 files

Coverage and gaps

Content covered in each file

These are the source ranges included in this check, not a guarantee that every issue has been resolved.

  • SKILL.mdFull text included
  • references/experiments.mdFull text included
  • references/form.mdFull text included
  • evals/evals.jsonFull text included

This report is for the version above. We read the available code and instructions without running the skill or checking extra packages it installs. This is not a promise of safety: a different version or setup may behave differently.

  • SKILL.mdInstructions
  • evals/evals.jsonSupporting file
  • references/experiments.mdSupporting file
  • references/form.mdSupporting file

Operations mentioned in code and instructions

Connect to websites
evals/evals.json:6In the instructionsOpen original file
      "id": 1,      "prompt": "Here's my SaaS landing page: https://example.com/product. We get about 5,000 visitors/month from Google Ads but only 1.2% convert to free trial signups. Can you help me figure out what's wrong?",      "expected_output": "Should check for product-marketing.md first. Should identify page type (landing page) and conversion goal (free trial signup). Should analyze across the CRO framework dimensions: value proposition clarity, headline 
Lines read
972
File checksum (to compare versions)
d0bca2e52f036b51efa320e0128841261e226bec17ec7b88f23870d07a0d7b0b