product-lens
Pass
Audited by Gen Agent Trust Hub on Aug 2, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill instructions define conceptual product management workflows including diagnostics, founder reviews, and journey audits. No executable malicious code or dangerous instructions are present.
- [EXTERNAL_DOWNLOADS]: Mode 3 (User Journey Audit) describes a workflow for cloning and installing products to document friction points. This is a functional requirement for auditing a software project and does not involve specific untrusted sources or automated remote script execution.
- [PROMPT_INJECTION]: Mode 2 (Founder Review) involves reading external project data such as README files, package.json manifests, and commit history. This represents a standard analysis surface required for the skill's diagnostic functions. Evidence: Ingestion points include README, CLAUDE.md, and package.json; Boundary markers for external content are absent; Capability inventory includes project installation; Sanitization logic is not specified for these inputs.
Audit Metadata