product-experience-officer
Pass
Audited by Gen Agent Trust Hub on Jul 13, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to autonomously identify and execute local entry-point scripts such as
install.sh,main.py, and scripts defined inpackage.json. It explicitly directs the agent to "find the way in without asking," which involves running shell commands and interactive programs via bash to simulate a product experience. - [PROMPT_INJECTION]: The skill is highly susceptible to indirect prompt injection because it is designed to ingest and act upon untrusted local and remote data.
- Ingestion points: Processes content from
README,install.sh, project source code, terminal transcripts, and live web pages via browser tools. - Boundary markers: Absent. The instructions mandate that the agent read and react to all product copy and labels without specifying delimiters or warnings to ignore embedded instructions.
- Capability inventory: Utilizes powerful capabilities including
bashfor shell command execution, browser tools for web interaction, andcomputer-usefor native application auditing. - Sanitization: No sanitization, escaping, or validation logic is provided for the data ingested during the auditing process.
Audit Metadata