product-experience-officer

Pass

Audited by Gen Agent Trust Hub on Jul 13, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to autonomously identify and execute local entry-point scripts such as install.sh, main.py, and scripts defined in package.json. It explicitly directs the agent to "find the way in without asking," which involves running shell commands and interactive programs via bash to simulate a product experience.
  • [PROMPT_INJECTION]: The skill is highly susceptible to indirect prompt injection because it is designed to ingest and act upon untrusted local and remote data.
  • Ingestion points: Processes content from README, install.sh, project source code, terminal transcripts, and live web pages via browser tools.
  • Boundary markers: Absent. The instructions mandate that the agent read and react to all product copy and labels without specifying delimiters or warnings to ignore embedded instructions.
  • Capability inventory: Utilizes powerful capabilities including bash for shell command execution, browser tools for web interaction, and computer-use for native application auditing.
  • Sanitization: No sanitization, escaping, or validation logic is provided for the data ingested during the auditing process.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 13, 2026, 09:59 AM
Security Audit — agent-trust-hub — product-experience-officer