product-sprint-prioritizer
Pass
Audited by Gen Agent Trust Hub on Mar 11, 2026
Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
- [PROMPT_INJECTION]: The skill has a surface for indirect prompt injection due to its ability to ingest untrusted data and perform file operations.\n
- Ingestion points: The agent uses
WebFetch,WebSearch, andReadtools inSKILL.mdto access external content.\n - Boundary markers: No delimiters or instructions are present to differentiate between system instructions and external data.\n
- Capability inventory: The
WriteandEdittools inSKILL.mdprovide a mechanism for an attacker to potentially modify files if the agent is manipulated.\n - Sanitization: No validation or sanitization of external input is implemented.\n- [NO_CODE]: The skill consists solely of markdown role definitions and contains no executable scripts or code blocks.
Audit Metadata