product-marketing
Pass
Audited by Gen Agent Trust Hub on Aug 26, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data from public websites and project documentation, creating a potential vector for malicious instructions to influence the agent's behavior.
- Ingestion points: Reads project README files, public product/pricing pages, and web-based documentation.
- Boundary markers: Includes a specific safety rule (Rule 2) instructing the agent to treat external web content as data and not as instructions.
- Capability inventory: The agent is authorized to write and update markdown files within the project's
.agents/or.claude/directories. - Sanitization: Requires evidence to be categorized into specific classes (e.g., Verified Fact vs. Hypothesis) and mandates the use of a validation plan to identify gaps and internal contradictions.
- [EXTERNAL_DOWNLOADS]: The skill instructions direct the agent to access external web pages for product, pricing, and documentation research, which involves performing network requests to non-specified external domains.
Audit Metadata