create-shape-up-pitch
Pass
Audited by Gen Agent Trust Hub on Jun 19, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill performs expected documentation tasks by reading from and writing to local project directories. It does not use network tools or access sensitive credentials.
- [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection via documentation ingestion. Evidence chain: (1) Ingestion points: .chalk/docs/product/, .chalk/docs/engineering/, and $ARGUMENTS. (2) Boundary markers: Absent. (3) Capability inventory: Read, Glob, Grep, and Write tools across SKILL.md. (4) Sanitization: Absent. The risk is inherent to the skill's purpose and does not indicate malicious intent.
Audit Metadata