product-manager-toolkit
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill contains Python scripts and documentation for product management workflows such as RICE prioritization and user research synthesis. Analysis of the scripts confirms they use standard libraries and perform only legitimate data processing on local files. No evidence of data exfiltration, remote code execution, or credential theft was found.
- [INDIRECT_PROMPT_INJECTION]: The skill includes tools to process external data sources like interview transcripts and CSV files. Ingestion points: scripts/customer_interview_analyzer.py and scripts/rice_prioritizer.py. Boundary markers and sanitization: The scripts lack specific delimiters or filtering for prompt injection markers. Capability inventory: The tools are limited to local regex matching and arithmetic, with no network or shell execution primitives. Therefore, while the surface exists, it does not present a path for high-risk exploitation.
Audit Metadata