startup-canvas
Pass
Audited by Gen Agent Trust Hub on Aug 10, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [SAFE]: The skill is composed of natural language instructions for product strategy and does not contain any executable scripts, binaries, or system commands.- [SAFE]: External references point to informational content on 'productcompass.pm' and a public Google Slides template, which are consistent with the skill's stated purpose.- [PROMPT_INJECTION]: The skill interpolates user-provided data via the $ARGUMENTS variable. Analysis of this surface shows: Ingestion point is the $ARGUMENTS variable; Boundary markers are absent; Capability inventory confirms no access to tools, network, or file system; Sanitization is absent. Despite the ingestion of untrusted data, the lack of functional capabilities makes this surface benign.
Audit Metadata