office-hours
Pass
Audited by Gen Agent Trust Hub on Apr 5, 2026
Risk Level: SAFE
Full Analysis
- [DATA_EXPOSURE]: The skill instructions direct the agent to read local project files such as README.md and package.json to establish context. This is standard behavior for development-oriented agents to understand the workspace and does not involve unauthorized data access or exfiltration.
- [INDIRECT_PROMPT_INJECTION]: The skill ingests user-provided descriptions of product ideas as part of the brainstorming process. While this represents an entry point for untrusted data, the skill's strict constraints—limiting output to text-based design documents and explicitly forbidding code generation—effectively mitigate the risk of malicious instructions being executed.
Audit Metadata