lyt-product-validation

Pass

Audited by Gen Agent Trust Hub on Sep 5, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to process untrusted external data, including CSV/XLSX files, competitor links (e.g., 1688), and screenshots, creating a surface for indirect prompt injection.
  • Ingestion points: SKILL.md and references/product-validation.md confirm the skill processes user-supplied tables and external web links.
  • Boundary markers: No explicit delimiters or instructions to ignore embedded commands within external data are defined in the instructions.
  • Capability inventory: The skill performs data extraction and logical evaluation on external content to generate reports.
  • Sanitization: No specific sanitization, filtering, or validation steps for ingested file content are documented.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 5, 2026, 12:23 PM
Security Audit — agent-trust-hub — lyt-product-validation