skills/affaan-m/ecc/product-lens/Gen Agent Trust Hub

product-lens

Pass

Audited by Gen Agent Trust Hub on Jun 16, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: The skill possesses an indirect prompt injection surface as it processes untrusted project data (README.md, CLAUDE.md, and commit messages). \n
  • Ingestion points: Project documentation and repository metadata. \n
  • Boundary markers: No explicit delimiters are specified to isolate untrusted data from the agent's instructions. \n
  • Capability inventory: File reading and potential command execution via project installation steps. \n
  • Sanitization: No content validation or sanitization routines are mentioned. \n- [COMMAND_EXECUTION]: The skill instructs the agent to clone and install products for user journey audits, which involves standard development tool execution (e.g., git, npm). \n- [DATA_EXFILTRATION]: While the skill scans for billing and Stripe integrations, it does so to identify product revenue signals for scoring and does not instruct the agent to exfiltrate credentials or keys.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 16, 2026, 02:47 PM
Security Audit — agent-trust-hub — product-lens