product-led-growth

Pass

Audited by Gen Agent Trust Hub on Sep 29, 2026

Risk Level: SAFENO_CODE
Full Analysis
  • [SAFE]: The skill is purely informational and strategic in nature, providing frameworks for business growth without any functional code components.
  • [NO_CODE]: There are no scripts (Python, JavaScript, Shell) or binaries included in the skill package. All logic is contained within Markdown text, and no external tools are requested or configured.
  • [INDIRECT_PROMPT_INJECTION]: The skill defines a clear ingestion surface for user-provided PLG scenarios but lacks any tools or capabilities (such as file writing or network access) that could be leveraged by an indirect injection attack.
  • Ingestion points: User requests in chat regarding PLG strategies (SKILL.md).
  • Boundary markers: Instructions explicitly mandate grounding in provided reference files and correcting the user if requests conflict with them.
  • Capability inventory: No tool access, no file system writes, and no network operations are present in the skill.
  • Sanitization: No explicit data sanitization is implemented, but the lack of executable capabilities renders this moot.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 29, 2026, 09:09 PM
Security Audit — agent-trust-hub — product-led-growth