product-owner

Pass

Audited by Gen Agent Trust Hub on Sep 19, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill possesses a surface for indirect prompt injection by ingesting and acting upon content from external repository files and user-supplied ideas.\n
  • Ingestion points: The skill reads project-specific documentation from paths such as docs/specs/*/README.md, docs/project-config.json, and docs/project-reference/.\n
  • Boundary markers: The instructions lack explicit boundary markers or directives to ignore instructions that might be embedded within the ingested documentation files.\n
  • Capability inventory: The skill is authorized to use the spawn_agent sub-agent and performs file system operations including Glob discovery and writing artifacts to the team-artifacts/ directory.\n
  • Sanitization: Technical sanitization or validation of the external content is absent, although the skill includes a cognitive instruction for the AI to remain skeptical and apply critical thinking.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 19, 2026, 12:17 PM
Security Audit — agent-trust-hub — product-owner