product-context-builder
Pass
Audited by Gen Agent Trust Hub on Aug 25, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface as it ingests untrusted repository content to generate durable instructions for AI agents.
- Ingestion points: The agent is instructed to read various files including package scripts, UI components, and product documentation across the entire repository (SKILL.md).
- Boundary markers: No programmatic boundary markers or delimiters are employed in the templates to separate ingested data from instructions.
- Capability inventory: The skill possesses read access to repository files and write access to generate or update context files (assets/templates/).
- Sanitization: There is no automated sanitization or instruction filtering for ingested content, relying exclusively on manual user validation (references/validation.md).
Audit Metadata