analytical-pm
Pass
Audited by Gen Agent Trust Hub on May 11, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [SAFE]: The skill serves as an instructional guide for AI product management and does not contain any scripts, command executions, or sensitive file access. All instructions are oriented towards professional development and persona adoption.
- [PROMPT_INJECTION]: Indirect prompt injection surface: The skill includes a 'Research-First Workflow' that directs the agent to perform 5-10 web searches to gather data for its response. This creates a surface where the agent could potentially ingest malicious instructions from external websites. However, this is a standard operational surface for research tasks and the skill does not grant the agent any high-risk capabilities. * Ingestion points: Web search results (SKILL.md). * Boundary markers: No explicit delimiter or instruction to ignore embedded search result commands is provided. * Capability inventory: The agent's capabilities are limited to text generation and web search; no file system or shell access is present. * Sanitization: The prompt does not specify sanitization or filtering of the retrieved web content.
Audit Metadata