product-manager-research-phase

Pass

Audited by Gen Agent Trust Hub on Sep 4, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONDYNAMIC_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to ingest data from untrusted sources, creating a surface for indirect prompt injection.
  • Ingestion points: The agent is directed to read local files such as README.md, AGENTS.md, docs, issues, and 'analytics exports' from the repository, as well as external content from competitor sites, app stores, and customer reviews.
  • Boundary markers: The skill does not define specific delimiters or instructions to ignore embedded commands within the researched material.
  • Capability inventory: The agent is authorized to read files, perform network operations for external research, and execute shell commands to run and audit applications.
  • Sanitization: No sanitization, validation, or filtering of the ingested content is specified before the agent processes it.
  • [COMMAND_EXECUTION]: The workflow requires the agent to execute code associated with the project under research.
  • The instruction "Run the app or inspect an existing environment when feasible" involves shell execution of the target codebase. If the repository being researched contains malicious scripts, the agent environment could be compromised during this discovery phase.
  • [DYNAMIC_EXECUTION]: The skill involves dynamic interaction with and execution of the target product's environment.
  • The agent is encouraged to walk primary workflows and inspect environment states, which requires runtime execution and interaction with potentially untrusted application code.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 4, 2026, 06:55 AM
Security Audit — agent-trust-hub — product-manager-research-phase