office-hours

Pass

Audited by Gen Agent Trust Hub on Apr 5, 2026

Risk Level: SAFE
Full Analysis
  • [DATA_EXPOSURE]: The skill instructions direct the agent to read local project files such as README.md and package.json to establish context. This is standard behavior for development-oriented agents to understand the workspace and does not involve unauthorized data access or exfiltration.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests user-provided descriptions of product ideas as part of the brainstorming process. While this represents an entry point for untrusted data, the skill's strict constraints—limiting output to text-based design documents and explicitly forbidding code generation—effectively mitigate the risk of malicious instructions being executed.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 5, 2026, 08:06 PM
Security Audit — agent-trust-hub — office-hours