product-capability

Pass

Audited by Gen Agent Trust Hub on Apr 6, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is purely instructional and contains no executable code or shell commands.
  • [PROMPT_INJECTION]: No patterns indicative of system prompt overrides, safety bypasses, or instruction-following manipulation were detected.
  • [DATA_EXFILTRATION]: The skill does not access sensitive file paths (e.g., .ssh, .env) and performs no network operations (e.g., curl, wget).
  • [REMOTE_CODE_EXECUTION]: There are no remote script downloads, piped executions, or external package dependencies defined.
  • [INDIRECT_PROMPT_INJECTION]: While the skill is designed to process untrusted data like PRDs or discussions, it lacks the dangerous capabilities (like network access or code execution) necessary to facilitate a high-risk indirect injection attack.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 6, 2026, 04:01 AM
Security Audit — agent-trust-hub — product-capability