product0-designing-experience
Pass
Audited by Gen Agent Trust Hub on Jul 13, 2026
Risk Level: SAFENO_CODEPROMPT_INJECTION
Full Analysis
- [SAFE]: The skill defines a structured product design workflow and does not include any executable scripts, network operations, or hardcoded credentials.
- [NO_CODE]: The skill consists only of instructional markdown and evaluation data; no source code files or binaries are provided.
- [PROMPT_INJECTION]: The skill operates on an external project brief, creating a surface for indirect prompt injection. 1. Ingestion points: The skill requires reading a 'canonical brief' (SKILL.md). 2. Boundary markers (absent): No explicit delimiters are specified to isolate untrusted data. 3. Capability inventory: The skill assumes project file read/write access to update the brief (SKILL.md). 4. Sanitization (absent): No content validation or sanitization process is described for external inputs.
Audit Metadata