product-audit
Pass
Audited by Gen Agent Trust Hub on Aug 31, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill analyzes untrusted data from the codebase, feature documentation (such as decisions.md and known-issues.md), and roadmap files. This creates a surface where maliciously crafted content in the analyzed project could attempt to influence the agent's findings or instructions.
- Ingestion points: Processes the entire codebase, feature-specific folders, project roadmaps, and issue trackers as specified in
SKILL.mdandreferences/AUDIT_PROCESS.md. - Boundary markers: The instructions do not specify the use of delimiters or 'ignore' instructions when reading project files into the context.
- Capability inventory: The skill utilizes tools for comprehensive file reading and is permitted to write report files to the
docs/audits/path and commit them to the repository. - Sanitization: The process does not describe specific filtering or sanitization of ingested content before evaluation.
Audit Metadata