user-stories
Pass
Audited by Gen Agent Trust Hub on Aug 10, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill instructions include a companion check mechanism that uses the
lscommand to verify if related product management skills are already installed in the user's environment. This is a functional utility used to provide relevant recommendations for complementary tools likeagile-scrumorproduct-strategyand does not access sensitive system files or credentials. - [EXTERNAL_DOWNLOADS]: The documentation references an installation method using
npxto add the skill to the agent's environment. This is the standard distribution method for this ecosystem and targets the provider's official repository. - [INDIRECT_PROMPT_INJECTION]: The skill possesses a data ingestion surface as it is designed to process user-provided feature descriptions and requirements to generate stories. While it has the capability to execute commands for environment discovery, the risk is minimal as the instructions focus on document analysis and template application rather than executing the contents of the processed data.
Audit Metadata