studio-distribute-scale-automate

Pass

Audited by Gen Agent Trust Hub on Aug 28, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted content from local tracker files and project documentation, which could contain malicious instructions designed to influence the agent's behavior during the roadmap generation process.
  • Ingestion points: The agent is instructed to read content from productos/distribute/3-Growth-Experiments-Tracker.md, productos/distribute/2-Growth-Experiments.md, productos/distribute/1-Go-To-Market-Strategy.md, and docs/PRODUCT.md.
  • Boundary markers: Absent. The instructions do not specify the use of delimiters or 'ignore' directives when processing the content of these external files.
  • Capability inventory: The agent has filesystem access to read project files and write the generated roadmap to productos/distribute/4-Scale-and-Automation-Roadmap.md or docs/scale-automation-roadmap.md.
  • Sanitization: Absent. There is no explicit requirement for the agent to sanitize, validate, or filter the content extracted from the tracker files before incorporating it into the final output.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 28, 2026, 10:33 PM
Security Audit — agent-trust-hub — studio-distribute-scale-automate