prd
Pass
Audited by Gen Agent Trust Hub on Aug 29, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes potentially untrusted content from existing files and user input to generate product strategy documents. \n
- Ingestion points: Reads contents from the
context/andresearch/directories of the workspace node to build product definitions. \n - Boundary markers: The instructions do not specify the use of delimiters or "ignore" instructions when processing the ingested content. \n
- Capability inventory: The skill has the capability to write multiple markdown files (e.g., README.md, vision.md, scope.md) to the local file system. \n
- Sanitization: There is no mention of sanitizing or validating the ingested content before it is incorporated into new strategic documents. \n- [COMMAND_EXECUTION]: The documentation includes instructions for the operator to run setup commands in the shell. \n
- Evidence: The text provides
npx skills add pedroromeroluna/ai-first-product-skillsas a command to install the skill package. \n - Context: The command targets a vendor-owned package associated with the skill author. \n- [EXTERNAL_DOWNLOADS]: The skill references external packages for installation via public registries. \n
- Evidence: Mentions the
pedroromeroluna/ai-first-product-skillspackage for retrieval via npx.
Audit Metadata