user-stories

Pass

Audited by Gen Agent Trust Hub on Aug 10, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructions include a companion check mechanism that uses the ls command to verify if related product management skills are already installed in the user's environment. This is a functional utility used to provide relevant recommendations for complementary tools like agile-scrum or product-strategy and does not access sensitive system files or credentials.
  • [EXTERNAL_DOWNLOADS]: The documentation references an installation method using npx to add the skill to the agent's environment. This is the standard distribution method for this ecosystem and targets the provider's official repository.
  • [INDIRECT_PROMPT_INJECTION]: The skill possesses a data ingestion surface as it is designed to process user-provided feature descriptions and requirements to generate stories. While it has the capability to execute commands for environment discovery, the risk is minimal as the instructions focus on document analysis and template application rather than executing the contents of the processed data.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 10, 2026, 02:06 PM
Security Audit — agent-trust-hub — user-stories