product-lens
Pass
Audited by Gen Agent Trust Hub on Sep 12, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill instructions direct the agent to analyze external, untrusted content which could contain malicious instructions or hidden payloads.
- Ingestion points: The skill (SKILL.md) instructs the agent in 'Founder Review' and 'User Journey Audit' modes to read local project files (README, CLAUDE.md, package.json), view recent commits, and clone/install external products.
- Boundary markers: The instructions lack boundary markers or explicit warnings to the agent to ignore instructions embedded within the files it analyzes.
- Capability inventory: While the skill contains no executable code of its own, it leverages the agent's capabilities to perform network operations (cloning) and system modifications (installing) based on untrusted external repositories.
- Sanitization: There is no requirement or guidance for the agent to sanitize or validate the content of the files before processing or executing installation steps.
Audit Metadata