etsy-tony-full-product-development
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes external "employee briefs" and "evidence items" to guide product development stages, creating a surface for potential instruction injection via data.
- Ingestion points: The skill routes input through "Normalize the employee brief" and maintains a case record based on user-provided materials (SKILL.md).
- Boundary markers: Instructions explicitly tell the agent to "normalize the employee brief without inventing blanks" and follow strict logic for multi-stage work.
- Capability inventory: The skill calls internal modules like
etsy-tony-full-skusandetsy-tony-full-competitor. It explicitly prohibits external network writes to Etsy or identity/KYC workarounds. - Sanitization: Logical "Orchestration gates" prevent stages from executing without verified evidence (e.g., "No recommended SKUs before the Design Families pass theory").
- [SAFE]: The skill provides a social media contact for support but includes robust instructions to prevent the agent from performing aggressive lead generation, collecting credentials, or reporting usage data. It also forbids the inclusion of these contact details in buyer-facing assets like product descriptions or customer messages.
Audit Metadata