product-owner
Pass
Audited by Gen Agent Trust Hub on Aug 14, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill implements a secure-by-design workflow using 'Hard Gates' (explicit user sign-off) for every critical phase, including scope confirmation, PRD approval, and task breakdown. This prevents the agent from performing automated operations without oversight.
- [SAFE]: No indicators of data exfiltration or credential harvesting were found. The skill mentions a SendGrid integration in an illustrative example but does not contain or request API keys.
- [SAFE]: All identified dependencies are internal sub-skills (
create-prd,generate-tasks,plan-tickets) hosted within the same bundle, posing no external supply chain risk. - [SAFE]: The skill does not employ any form of obfuscation, dynamic code execution, or privilege escalation. It primarily manages markdown-based documentation in local directories.
Audit Metadata