workflow-product-discovery
Pass
Audited by Gen Agent Trust Hub on May 1, 2026
Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [PROMPT_INJECTION]: The skill uses instructional language to enforce workflow compliance and quality standards, such as 'Anti-hallucination' and 'Critical Thinking' mindsets. These directives are intended to optimize task execution and accuracy rather than overriding safety guardrails. Additionally, the skill defines a surface for indirect prompt injection by processing user-provided product visions. Ingestion points: The agent takes 'raw product vision or problem' as context for the discovery workflow. Boundary markers: While the workflow is highly structured with clear task definitions, it does not explicitly delimit the user input to prevent instruction leakage. Capability inventory: The skill can create tasks, write to the project filesystem, and spawn sub-agents. Sanitization: No explicit validation or filtering of user input is documented, relying on the agent's internal reasoning and human-in-the-loop checkpoints like '/why-review'.
- [COMMAND_EXECUTION]: The skill utilizes tools like TaskCreate and mentions sub-agent orchestration. These actions are transparently integrated into the workflow for managing tasks and processing complex product discovery stages.
- [EXTERNAL_DOWNLOADS]: A /web-research step is defined for domain analysis. This is a framework-native capability for information gathering and does not represent a risk of downloading and executing malicious external code.
Audit Metadata