product-manager

Pass

Audited by Gen Agent Trust Hub on May 1, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [PROMPT_INJECTION]: Susceptible to indirect prompt injection via ingestion of external and internal agent data.
  • Ingestion points: The skill reads handoff packages from local paths such as .forgewright/business-analyst/handoff/ba-package.md and fetches external data using search_web and read_url_content tools.
  • Boundary markers: Absent. The instructions do not define delimiters or provide warnings to the agent to ignore instructions within the ingested data.
  • Capability inventory: The skill can write files to the project root, spawn autonomous subagents via the Agent tool, and perform web research.
  • Sanitization: There is no evidence of sanitization or structural validation for the external content before it is processed by the agent.
  • [COMMAND_EXECUTION]: Employs dynamic context injection to execute shell commands during the skill loading process.
  • Evidence: Uses the !cat syntax (e.g., !cat .production-grade.yaml) to silently read local configuration and protocol files into the session context.
  • [COMMAND_EXECUTION]: Programmatically spawns subagents to perform verification tasks.
  • Evidence: Utilizes the Agent tool with subagent_type: general-purpose to autonomously verify implementation compliance against documented requirements.
  • [EXTERNAL_DOWNLOADS]: Conducts automated web research to retrieve domain and competitive information.
  • Evidence: Utilizes search_web and read_url_content to fill information gaps during the requirement gathering phase.
Audit Metadata
Risk Level
SAFE
Analyzed
May 1, 2026, 08:02 AM
Security Audit — agent-trust-hub — product-manager