product-lens
Pass
Audited by Gen Agent Trust Hub on Apr 1, 2026
Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
- [NO_CODE]: The skill is composed entirely of markdown instructions and does not bundle any scripts, binaries, or automated configuration files for code execution.\n- [COMMAND_EXECUTION]: The 'User Journey Audit' mode instructs the agent to clone and install products. While this requires executing external commands and software, it is presented as a functional step for the auditing process rather than a hidden or malicious operation.\n- [PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection because it reads and processes data from untrusted external sources.\n
- Ingestion points: The agent reads project-specific metadata and documentation, including README, CLAUDE.md, package.json, and git commit history.\n
- Boundary markers: There are no specified delimiters or instructions to treat project content as data rather than instructions.\n
- Capability inventory: The skill involves reading local project files and suggests executing installation routines for software auditing.\n
- Sanitization: No mechanisms for sanitizing, escaping, or validating the content of the audited project files are defined.
Audit Metadata