foundation-build-risk-review

Pass

Audited by Gen Agent Trust Hub on Aug 27, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted user input describing product ideas, feature requests, or scope changes to generate a structured risk assessment and determine the next logical step in a product workflow.
  • Ingestion points: The skill accepts raw product ideas and feature requests as defined in the SKILL.md instructions and demonstrated in the evals/output-scenarios/ai-meeting-summarizer.md example.
  • Capability inventory: The skill is primarily instructional and generates text artifacts. It does not perform network operations, local file writes, or shell command execution. However, it directs the agent to subsequent skills (e.g., define-problem-statement, deliver-prd), meaning a malicious input could attempt to influence the entire downstream chain.
  • Boundary markers: The skill lacks explicit delimiters (such as XML tags or triple quotes) to encapsulate the user-provided idea, increasing the risk of the agent conflating user input with its own instructions.
  • Sanitization: No input validation or sanitization mechanisms are specified for the provided product descriptions.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 27, 2026, 09:21 AM
Security Audit — agent-trust-hub — foundation-build-risk-review