product-domain-engine
Pass
Audited by Gen Agent Trust Hub on Sep 27, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill defines a philosophical and technical protocol for product domain analysis. All provided documentation, templates, and orchestration logic follow standard practices for systemic development.
- [COMMAND_EXECUTION]: The skill includes
scripts/domain-audit.sh, a bash utility that audits repository health by counting files and checking git metadata. The script correctly uses command substitution and quotes variables to prevent shell injection. Furthermore, it utilizesjqto ensure all metadata strings are properly escaped before being output as JSON for agent consumption. - [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted metadata from external repositories (such as file names, directory structures, and git logs) through its auditing script. This risk is managed and deemed safe for the following reasons:
- Ingestion points: Repository metadata ingested by
scripts/domain-audit.sh(filenames, git history, line counts). - Boundary markers: The audit results are presented to the agent in structured formats (JSON/Text).
- Capability inventory: The skill orchestrates analysis and requirements design skills; no dangerous capabilities are directly exposed to raw file content.
- Sanitization: The script uses
jqto sanitize all ingested metadata, ensuring that special characters in file names do not cause confusion in the JSON structure.
Audit Metadata