product-map
Pass
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill presents an attack surface for indirect prompt injection because it processes untrusted codebase content and application data to generate documentation.
- Ingestion points: The agent is instructed to read the entire repository, including routes, handlers, models, and tests, and to explore the running application's UI (SKILL.md).
- Boundary markers: The instructions do not specify the use of delimiters or warnings to ignore embedded instructions when reading source code or application state.
- Capability inventory: The skill can execute shell commands (npm, pnpm, yarn, bun, python3), write files to the /product directory, install Node.js packages, and start a local web server (SKILL.md).
- Sanitization: There is no explicit requirement to sanitize or escape data ingested from the codebase before it is used to generate Markdown documentation.
- [COMMAND_EXECUTION]: The skill directs the agent to execute various shell commands to set up the environment and validate output.
- Evidence: SKILL.md provides instructions for installing dependencies using npm/pnpm/yarn/bun, running the documentation viewer, and executing the bundled Python validation script.
- [EXTERNAL_DOWNLOADS]: The skill automates the installation of a development dependency from an external registry.
- Evidence: The agent is instructed to install the @nuthinking/product-map package from npm using the project's package manager (SKILL.md).
- [DYNAMIC_EXECUTION]: The skill uses a local Python script to perform structural validation of the generated Product Map.
- Evidence: The scripts/validate.py script is executed by the agent and copied into the user's repository (product/validate.py) for use in CI and by other teammates (SKILL.md, scripts/validate.py).
Audit Metadata