product-teardown

Pass

Audited by Gen Agent Trust Hub on Aug 14, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill consists entirely of natural language instructions and does not include any scripts, external dependencies, or hidden commands. The operational logic is confined to analysis and documentation.
  • [INDIRECT_PROMPT_INJECTION]: The skill involves analyzing external content, which presents a standard attack surface for indirect prompt injection.
  • Ingestion points: The agent is instructed to analyze external URLs, public web pages, and target repositories (SKILL.md).
  • Boundary markers: No specific delimiters or instructions to ignore embedded commands in external artifacts are defined.
  • Capability inventory: The workflow permits inspecting and proposing changes to target repositories (SKILL.md, Workflow step 6).
  • Sanitization: There are no requirements for sanitizing or validating the content of the external pages or repositories processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 14, 2026, 06:57 AM
Security Audit — agent-trust-hub — product-teardown