positioning-workshop
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill operates as a structured text interaction designed to assist product managers. It does not contain executable code, system commands, or network requests. All logic is strictly instructional for the AI agent to facilitate a workshop.
- [INDIRECT_PROMPT_INJECTION]: The skill includes a step to gather external product context, such as website copy and customer testimonials, which represents a potential ingestion surface for indirect prompt injection. However, since the skill only outputs formatted text and lacks tools or capabilities such as file writing, network access, or shell command execution, the security risk is assessed as safe. 1. Ingestion points: Step 0: Gather Context (SKILL.md). 2. Boundary markers: Uses context-specific phrasing ('Based on the context provided') to scope the focus. 3. Capability inventory: No dangerous capabilities (file, network, or process execution) are present in the skill definition. 4. Sanitization: Relies on default model guardrails; no specific sanitization instructions are included.
Audit Metadata