product-manager
Pass
Audited by Gen Agent Trust Hub on May 1, 2026
Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [PROMPT_INJECTION]: Susceptible to indirect prompt injection via ingestion of external and internal agent data.
- Ingestion points: The skill reads handoff packages from local paths such as .forgewright/business-analyst/handoff/ba-package.md and fetches external data using search_web and read_url_content tools.
- Boundary markers: Absent. The instructions do not define delimiters or provide warnings to the agent to ignore instructions within the ingested data.
- Capability inventory: The skill can write files to the project root, spawn autonomous subagents via the Agent tool, and perform web research.
- Sanitization: There is no evidence of sanitization or structural validation for the external content before it is processed by the agent.
- [COMMAND_EXECUTION]: Employs dynamic context injection to execute shell commands during the skill loading process.
- Evidence: Uses the !cat syntax (e.g., !cat .production-grade.yaml) to silently read local configuration and protocol files into the session context.
- [COMMAND_EXECUTION]: Programmatically spawns subagents to perform verification tasks.
- Evidence: Utilizes the Agent tool with subagent_type: general-purpose to autonomously verify implementation compliance against documented requirements.
- [EXTERNAL_DOWNLOADS]: Conducts automated web research to retrieve domain and competitive information.
- Evidence: Utilizes search_web and read_url_content to fill information gaps during the requirement gathering phase.
Audit Metadata