product-vision

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill contains no executable code, shell commands, network requests, or attempts to override system safety guardrails.
  • [INDIRECT_PROMPT_INJECTION]: The instructions note that the agent may read files from the user's workspace to gather product and company context. While this introduces an ingestion point for untrusted data, the skill possesses no capabilities (such as file-writing tools or network components) that could be exploited via indirect prompt injection, rendering the surface safe.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 12:02 PM
Security Audit — agent-trust-hub — product-vision