idea-development
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill operates as a high-level instructional framework for product management tasks. It relies on local markdown templates and reference guides to structure AI responses. No evidence of command execution, credential access, obfuscation, or unauthorized network operations was found.
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process user-provided product ideas and external validation documents. While this creates an entry point for untrusted data, the skill's scope is limited to document generation within the project's documentation directory, and it lacks high-privilege capabilities such as shell access or external network connectivity.
- Ingestion points: Processes informal user idea descriptions and
validation-brief.mdfiles (SKILL.md, Step 7). - Boundary markers: No explicit instruction delimiters or 'ignore' directives are defined for user-provided inputs.
- Capability inventory: The skill is configured to generate text and write to documentation files (docs/product/); no dangerous system tools or network utilities are invoked.
- Sanitization: Relies on the underlying model's safety guardrails; no specific input validation or escaping logic is implemented in the skill instructions.
Audit Metadata