stelow-product-discovery
Pass
Audited by Gen Agent Trust Hub on Sep 8, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill provides structured educational content and interaction guidelines based on a specific methodology. No malicious patterns or security risks were identified.
- [INDIRECT_PROMPT_INJECTION]: The skill processes user input to provide methodology-based advice. While it lacks explicit input sanitization markers for user-provided context, this is a standard behavior for reference-based conversational skills and represents an inherent but minimal risk profile.
- [EXTERNAL_DOWNLOADS]: The documentation references multiple third-party tools (e.g., Tally, Gumroad, Glimpse) as recommendations for the user's external business processes. The agent itself does not interact with these services or perform remote downloads.
- [DYNAMIC_EXECUTION]: The skill contains a block of shell code intended as logic for the agent to detect its execution environment (via STELOW_WORKFLOW and STELOW_STATE variables) to switch between standalone and workflow modes. This is a legitimate state-management mechanism and not an execution risk.
Audit Metadata