product-domain-engine

Pass

Audited by Gen Agent Trust Hub on Sep 27, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill defines a philosophical and technical protocol for product domain analysis. All provided documentation, templates, and orchestration logic follow standard practices for systemic development.
  • [COMMAND_EXECUTION]: The skill includes scripts/domain-audit.sh, a bash utility that audits repository health by counting files and checking git metadata. The script correctly uses command substitution and quotes variables to prevent shell injection. Furthermore, it utilizes jq to ensure all metadata strings are properly escaped before being output as JSON for agent consumption.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted metadata from external repositories (such as file names, directory structures, and git logs) through its auditing script. This risk is managed and deemed safe for the following reasons:
  • Ingestion points: Repository metadata ingested by scripts/domain-audit.sh (filenames, git history, line counts).
  • Boundary markers: The audit results are presented to the agent in structured formats (JSON/Text).
  • Capability inventory: The skill orchestrates analysis and requirements design skills; no dangerous capabilities are directly exposed to raw file content.
  • Sanitization: The script uses jq to sanitize all ingested metadata, ensuring that special characters in file names do not cause confusion in the JSON structure.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 27, 2026, 06:53 PM
Security Audit — agent-trust-hub — product-domain-engine