product-grill

Pass

Audited by Gen Agent Trust Hub on Sep 4, 2026

Risk Level: SAFENO_CODEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill instructions define a structured interview process for product development and do not contain any malicious patterns such as prompt injection, obfuscation, or data exfiltration attempts.
  • [NO_CODE]: The skill consists entirely of natural language instructions and markdown examples. It does not include or execute any scripts, binaries, or third-party packages.
  • [INDIRECT_PROMPT_INJECTION]: The skill maintains context by reading from and writing to local files.
  • Ingestion points: Reads existing conviction brief files as specified in SKILL.md.
  • Boundary markers: None present in the document structure instructions.
  • Capability inventory: The skill possesses no subprocess calls, file-write to sensitive paths, network operations, or dynamic code execution capabilities across any of its components.
  • Sanitization: No sanitization or escaping of external content is specified. This attack surface is considered safe given the skill's restricted capabilities.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 4, 2026, 01:31 PM
Security Audit — agent-trust-hub — product-grill