product-name-extractor

Pass

Audited by Gen Agent Trust Hub on Aug 8, 2026

Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
  • [PROMPT_INJECTION]: The skill processes untrusted user input to extract product names, creating a surface for indirect prompt injection where instructions could be hidden in the processed data.
  • Ingestion points: User-provided text such as descriptions, articles, and conversations defined in the workflow of SKILL.md.
  • Boundary markers: The instructions do not define delimiters or markers to isolate the user's data from the prompt's task logic.
  • Capability inventory: Analysis of the skill reveals no dangerous capabilities such as network access, file system writes, or shell command execution.
  • Sanitization: No input sanitization or validation logic is defined to filter out potential injection attempts.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 8, 2026, 04:17 AM
Security Audit — agent-trust-hub — product-name-extractor