authoring-user-flows

Pass

Audited by Gen Agent Trust Hub on Jun 25, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill consists entirely of instructional markdown files and reference documentation for product design workflows. No executable code or suspicious command patterns were found.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to process Product Requirements Documents (PRDs) as input (ingestion point in SKILL.md). While this represents a potential surface for indirect prompt injection, the skill includes explicit instructions to 'derive, don't invent' and trace all flows back to specific PRD goals, which serves as a manual verification step. It does not utilize automated scripts to process this data in a way that would trigger command execution or data exfiltration.
  • [EXTERNAL_DOWNLOADS]: The skill references the use of standard research capabilities (such as 'deep-research') and template tools. These are used for gathering domain conventions and providing document structure, respectively, and do not involve downloading or executing untrusted code.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 25, 2026, 05:45 AM
Security Audit — agent-trust-hub — authoring-user-flows