authoring-user-flows
Pass
Audited by Gen Agent Trust Hub on Jun 25, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill consists entirely of instructional markdown files and reference documentation for product design workflows. No executable code or suspicious command patterns were found.
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to process Product Requirements Documents (PRDs) as input (ingestion point in SKILL.md). While this represents a potential surface for indirect prompt injection, the skill includes explicit instructions to 'derive, don't invent' and trace all flows back to specific PRD goals, which serves as a manual verification step. It does not utilize automated scripts to process this data in a way that would trigger command execution or data exfiltration.
- [EXTERNAL_DOWNLOADS]: The skill references the use of standard research capabilities (such as 'deep-research') and template tools. These are used for gathering domain conventions and providing document structure, respectively, and do not involve downloading or executing untrusted code.
Audit Metadata