product-manager-brainstorm-phase
Pass
Audited by Gen Agent Trust Hub on Sep 4, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes content from external data sources which represents a potential attack surface for indirect instructions.
- Ingestion points: The skill reads
research.md,evidence-log.md,AGENTS.md, and existing project roadmaps or issues from the file system. - Boundary markers: No explicit delimiters or instructions are provided to the agent to treat the content of these files as data rather than instructions.
- Capability inventory: The agent is directed to read multiple files and write a new file (
candidate-matrix.md). - Sanitization: There is no evidence of content validation or sanitization for the data ingested from the project files.
Audit Metadata