create-shape-up-pitch

Pass

Audited by Gen Agent Trust Hub on Jun 19, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill performs expected documentation tasks by reading from and writing to local project directories. It does not use network tools or access sensitive credentials.
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection via documentation ingestion. Evidence chain: (1) Ingestion points: .chalk/docs/product/, .chalk/docs/engineering/, and $ARGUMENTS. (2) Boundary markers: Absent. (3) Capability inventory: Read, Glob, Grep, and Write tools across SKILL.md. (4) Sanitization: Absent. The risk is inherent to the skill's purpose and does not indicate malicious intent.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 19, 2026, 10:42 AM
Security Audit — agent-trust-hub — create-shape-up-pitch