signup

Pass

Audited by Gen Agent Trust Hub on Aug 2, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: Analysis of the skill instructions and evaluation cases confirms the tool is a purely consultative advisor. It contains no executable code, obfuscated content, or persistence mechanisms.- [SAFE]: The skill presents an indirect prompt injection surface as it ingests untrusted data from project context files (e.g., .agents/product-marketing.md). Evidence chain: 1. Ingestion points: .agents/product-marketing.md, .claude/product-marketing.md, product-marketing-context.md. 2. Boundary markers: Absent. 3. Capability inventory: File reading for context. 4. Sanitization: Absent. The risk is considered minimal as the skill only generates text-based recommendations.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 2, 2026, 03:59 PM
Security Audit — agent-trust-hub — signup