product-audit

Pass

Audited by Gen Agent Trust Hub on Aug 31, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill analyzes untrusted data from the codebase, feature documentation (such as decisions.md and known-issues.md), and roadmap files. This creates a surface where maliciously crafted content in the analyzed project could attempt to influence the agent's findings or instructions.
  • Ingestion points: Processes the entire codebase, feature-specific folders, project roadmaps, and issue trackers as specified in SKILL.md and references/AUDIT_PROCESS.md.
  • Boundary markers: The instructions do not specify the use of delimiters or 'ignore' instructions when reading project files into the context.
  • Capability inventory: The skill utilizes tools for comprehensive file reading and is permitted to write report files to the docs/audits/ path and commit them to the repository.
  • Sanitization: The process does not describe specific filtering or sanitization of ingested content before evaluation.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 31, 2026, 01:15 PM
Security Audit — agent-trust-hub — product-audit