studio-define-from-code

Pass

Audited by Gen Agent Trust Hub on Aug 28, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from live product URLs, landing pages, app store listings, and existing codebase content. An attacker could embed malicious instructions in these external sources (e.g., in HTML comments, hidden text, or code documentation) that the agent might follow when drafting the strategy documents.
  • Ingestion points: SKILL.md specifies reading the local codebase, live product URLs, landing pages, and app store listings.
  • Boundary markers: The skill lacks specific instructions for the agent to treat external content as untrusted or to use delimiters to separate source data from its own instructions.
  • Capability inventory: The agent has the capability to read the local filesystem and external URLs, and write files to the productos/define/ directory.
  • Sanitization: No sanitization or filtering of the ingested external content is described.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 28, 2026, 10:33 PM
Security Audit — agent-trust-hub — studio-define-from-code