product-capability
Pass
Audited by Gen Agent Trust Hub on Sep 1, 2026
Risk Level: SAFE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to process external, untrusted data such as project issues, discussions, and founder notes. This creates a potential surface for indirect prompt injection where malicious instructions could be embedded in the source product requirements. However, the skill's intended use is strictly for creating static documentation (SRS-style plans) and it does not utilize tools for code execution, network access, or privilege escalation, making the risk negligible.
- Ingestion points: SKILL.md (Inputs section) lists reading issues, discussions, PRDs, and roadmap notes.
- Boundary markers: No explicit delimiters for untrusted content are defined.
- Capability inventory: The skill instructions are limited to reading repository documentation and writing to local markdown files (e.g., PRODUCT.md). No high-risk tools (shell, network, etc.) are suggested or required.
- Sanitization: No explicit sanitization of external input is requested.
Audit Metadata