foundation-build-risk-review
Pass
Audited by Gen Agent Trust Hub on Aug 27, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted user input describing product ideas, feature requests, or scope changes to generate a structured risk assessment and determine the next logical step in a product workflow.
- Ingestion points: The skill accepts raw product ideas and feature requests as defined in the
SKILL.mdinstructions and demonstrated in theevals/output-scenarios/ai-meeting-summarizer.mdexample. - Capability inventory: The skill is primarily instructional and generates text artifacts. It does not perform network operations, local file writes, or shell command execution. However, it directs the agent to subsequent skills (e.g.,
define-problem-statement,deliver-prd), meaning a malicious input could attempt to influence the entire downstream chain. - Boundary markers: The skill lacks explicit delimiters (such as XML tags or triple quotes) to encapsulate the user-provided idea, increasing the risk of the agent conflating user input with its own instructions.
- Sanitization: No input validation or sanitization mechanisms are specified for the provided product descriptions.
Audit Metadata