product-owner
Pass
Audited by Gen Agent Trust Hub on Sep 19, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill possesses a surface for indirect prompt injection by ingesting and acting upon content from external repository files and user-supplied ideas.\n
- Ingestion points: The skill reads project-specific documentation from paths such as
docs/specs/*/README.md,docs/project-config.json, anddocs/project-reference/.\n - Boundary markers: The instructions lack explicit boundary markers or directives to ignore instructions that might be embedded within the ingested documentation files.\n
- Capability inventory: The skill is authorized to use the
spawn_agentsub-agent and performs file system operations includingGlobdiscovery and writing artifacts to theteam-artifacts/directory.\n - Sanitization: Technical sanitization or validation of the external content is absent, although the skill includes a cognitive instruction for the AI to remain skeptical and apply critical thinking.
Audit Metadata