systemic-product-analyst

Pass

Audited by Gen Agent Trust Hub on Sep 27, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill's core functionality relies on ingesting untrusted data from the user (such as product claims, metrics, and task outcomes) to perform its analysis. This creates a surface where malicious instructions could be embedded in the data provided to the agent.
  • Ingestion points: Product details, primary user contexts, and claim evidence requested in SKILL.md under the 'Intake & Snapshot' and 'Run the Diagnostics' sections.
  • Boundary markers: The skill does not provide instructions to the agent to treat user data as untrusted or to ignore embedded instructions (e.g., within the 'Claim Stack' or 'Outcome Test' data).
  • Capability inventory: The skill is restricted to generating markdown artifacts and providing text analysis. It does not perform network operations, file system modifications (outside of artifact generation), or subprocess execution.
  • Sanitization: No sanitization or filtering logic is specified for the user-provided content before it is interpolated into analysis artifacts.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 27, 2026, 06:52 PM
Security Audit — agent-trust-hub — systemic-product-analyst