prd

Pass

Audited by Gen Agent Trust Hub on Aug 29, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes potentially untrusted content from existing files and user input to generate product strategy documents. \n
  • Ingestion points: Reads contents from the context/ and research/ directories of the workspace node to build product definitions. \n
  • Boundary markers: The instructions do not specify the use of delimiters or "ignore" instructions when processing the ingested content. \n
  • Capability inventory: The skill has the capability to write multiple markdown files (e.g., README.md, vision.md, scope.md) to the local file system. \n
  • Sanitization: There is no mention of sanitizing or validating the ingested content before it is incorporated into new strategic documents. \n- [COMMAND_EXECUTION]: The documentation includes instructions for the operator to run setup commands in the shell. \n
  • Evidence: The text provides npx skills add pedroromeroluna/ai-first-product-skills as a command to install the skill package. \n
  • Context: The command targets a vendor-owned package associated with the skill author. \n- [EXTERNAL_DOWNLOADS]: The skill references external packages for installation via public registries. \n
  • Evidence: Mentions the pedroromeroluna/ai-first-product-skills package for retrieval via npx.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 29, 2026, 05:23 AM
Security Audit — agent-trust-hub — prd