pricing
Pass
Audited by Gen Agent Trust Hub on Aug 30, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill consists of informational markdown files and evaluation data. It lacks any commands, scripts, or network capabilities that could be used for malicious purposes.
- [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to read local configuration files (e.g.,
.agents/product-marketing.md) to provide context-aware pricing advice. This represents a data ingestion surface. - Ingestion points:
SKILL.mddirects the agent to read marketing context files if they exist in the project directory. - Boundary markers: The instructions do not define specific delimiters or "ignore instructions" wrappers for the ingested content.
- Capability inventory: The skill is purely advisory; it contains no file-write, network exfiltration, or shell execution capabilities across its documentation and reference files.
- Sanitization: No sanitization or validation of the ingested context file content is performed.
Audit Metadata