product0-slicing-scope

Pass

Audited by Gen Agent Trust Hub on Jul 13, 2026

Risk Level: SAFENO_CODE
Full Analysis
  • [SAFE]: The skill consists of natural language instructions for product management workflows. No malicious patterns, hidden code, or dangerous operations were identified.
  • [NO_CODE]: There are no executable files, scripts (.py, .js, .sh), or compiled binaries included in this skill. All logic is contained within markdown instructions and evaluation criteria.
  • [PROMPT_INJECTION]: The skill is designed to ingest and process a 'canonical brief' which acts as an untrusted data source, creating a surface for indirect prompt injection.
  • Ingestion points: Processes the 'canonical brief' as specified in SKILL.md.
  • Boundary markers: Lacks explicit delimiters or 'ignore embedded instructions' warnings for the agent when reading external content.
  • Capability inventory: The skill utilizes project file read and write access for documentation maintenance.
  • Sanitization: No input validation or sanitization is performed on the content of the brief before processing.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 13, 2026, 01:47 PM
Security Audit — agent-trust-hub — product0-slicing-scope