funnel
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONNO_CODE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill architecture relies on the ingestion of untrusted data from external sources. * Ingestion points: Requirements, persona data, and competitor analysis enter the context through structured handoffs defined in SKILL.md and reference/handoffs.md. * Boundary markers: The skill utilizes YAML delimiters for handoffs but lacks specific instructions to ignore embedded prompts within the variable content. * Capability inventory: The skill directs file writes to project logs and generates instructions for code-writing agents. * Sanitization: No evidence of input validation or sanitization for third-party text content was found.
- [NO_CODE]: The skill contains only documentation and configuration files. There are no executable scripts, reducing the direct execution attack surface.
Audit Metadata