product-capability

Pass

Audited by Gen Agent Trust Hub on Sep 1, 2026

Risk Level: SAFE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to process external, untrusted data such as project issues, discussions, and founder notes. This creates a potential surface for indirect prompt injection where malicious instructions could be embedded in the source product requirements. However, the skill's intended use is strictly for creating static documentation (SRS-style plans) and it does not utilize tools for code execution, network access, or privilege escalation, making the risk negligible.
  • Ingestion points: SKILL.md (Inputs section) lists reading issues, discussions, PRDs, and roadmap notes.
  • Boundary markers: No explicit delimiters for untrusted content are defined.
  • Capability inventory: The skill instructions are limited to reading repository documentation and writing to local markdown files (e.g., PRODUCT.md). No high-risk tools (shell, network, etc.) are suggested or required.
  • Sanitization: No explicit sanitization of external input is requested.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 1, 2026, 02:38 AM
Security Audit — agent-trust-hub — product-capability