product-context-builder

Pass

Audited by Gen Agent Trust Hub on Aug 25, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface as it ingests untrusted repository content to generate durable instructions for AI agents.
  • Ingestion points: The agent is instructed to read various files including package scripts, UI components, and product documentation across the entire repository (SKILL.md).
  • Boundary markers: No programmatic boundary markers or delimiters are employed in the templates to separate ingested data from instructions.
  • Capability inventory: The skill possesses read access to repository files and write access to generate or update context files (assets/templates/).
  • Sanitization: There is no automated sanitization or instruction filtering for ingested content, relying exclusively on manual user validation (references/validation.md).
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 25, 2026, 07:35 PM
Security Audit — agent-trust-hub — product-context-builder