product-name-extractor
Pass
Audited by Gen Agent Trust Hub on Aug 8, 2026
Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
- [PROMPT_INJECTION]: The skill processes untrusted user input to extract product names, creating a surface for indirect prompt injection where instructions could be hidden in the processed data.
- Ingestion points: User-provided text such as descriptions, articles, and conversations defined in the workflow of SKILL.md.
- Boundary markers: The instructions do not define delimiters or markers to isolate the user's data from the prompt's task logic.
- Capability inventory: Analysis of the skill reveals no dangerous capabilities such as network access, file system writes, or shell command execution.
- Sanitization: No input sanitization or validation logic is defined to filter out potential injection attempts.
Audit Metadata