ln-12-product-requirements-builder
Pass
Audited by Gen Agent Trust Hub on Oct 3, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill provides instructions for documentation workflows and requirement validation. It contains specific guardrails such as 'do not invent commitments, design architecture, or implement' and 'Change only authorized product documentation'. There are no indications of unauthorized command execution, persistence, or network exfiltration.
- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from repository instructions, user evidence, and target files (SKILL.md). No explicit boundary markers or sanitization logic are defined for this processed content. However, the capability inventory is strictly limited to editing product requirements artifacts, and the skill does not use dangerous tools like shells or network requests, which effectively mitigates the potential impact of indirect injections.
Audit Metadata