battle-card-builder

Pass

Audited by Gen Agent Trust Hub on Sep 22, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and summarize untrusted external data from the web (pricing pages, release notes, and customer reviews) to generate competitive artifacts. Identifying this surface is standard for research skills.\n
  • Ingestion points: Web search results, external documentation pages, and customer review platforms (referenced in SKILL.md).\n
  • Boundary markers: The prompt emphasizes the use of Fact/Inference/Assumption labels and an evidence table, but it does not specify explicit boundary delimiters to isolate external text from the agent's core instructions.\n
  • Capability inventory: The skill utilizes web browsing and drafting capabilities to compile research into a structured markdown schema.\n
  • Sanitization: No explicit procedures for sanitizing or filtering instructions that might be embedded in the retrieved web content are defined.\n- [EXTERNAL_DOWNLOADS]: The skill's documentation includes a reference to a third-party GitHub repository (https://github.com/deanpeters/product-manager-prompts) as a source for its methodology. This is provided for attribution purposes and does not involve the automated download or execution of scripts.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 22, 2026, 02:56 PM
Security Audit — agent-trust-hub — battle-card-builder