qe-sfdipot-product-factors
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze untrusted external data, including requirement documents, epics, and specifications, to generate test plans.
- Ingestion points: Untrusted content enters the agent's context through requirements, epics, user stories, and specifications analyzed in the
qe-product-factors-assessortask. - Boundary markers: The skill does not define or use explicit delimiters or "ignore instructions" warnings when interpolating the content of documents like
epicDocumentinto its analysis workflow. - Capability inventory: The skill's primary capabilities are limited to text generation (generating test ideas, clarifying questions, and assigning priorities). It does not contain evidence of dangerous capabilities such as direct shell command execution, file system modification, or non-whitelisted network operations.
- Sanitization: There is no evidence of escaping, validation, or filtering mechanisms for the external document content before it is processed by the agent.
Audit Metadata