product-pricing-strategy

Warn

Audited by Gen Agent Trust Hub on Jul 8, 2026

Risk Level: MEDIUMPROMPT_INJECTIONNO_CODE
Full Analysis
  • [PROMPT_INJECTION]: The skill includes over 1,200 sections of repetitive technical filler across eight files (e.g., references/architecture-patterns.md, references/security-best-practices.md) that are not even referenced by the main SKILL.md. Each section contains technical content about kernel optimization and circuit breakers that is entirely unrelated to pricing strategy. This massive bloat acts as a 'prompt bomb' that can exhaust context windows, hide malicious instructions, or distract the AI model from its core protocols.
  • [PROMPT_INJECTION]: The agent is instructed to ingest and analyze untrusted data regarding 'competitor pricing models' and 'target customer segments' without any boundary markers, delimiters, or sanitization instructions, creating a vulnerability to indirect prompt injection (SKILL.md).
  • [NO_CODE]: The skill consists entirely of Markdown and configuration files with no executable scripts (.py, .js, .sh), which limits its ability to perform direct malicious operations such as network exfiltration or local command execution.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Jul 8, 2026, 12:23 PM
Security Audit — agent-trust-hub — product-pricing-strategy