product-manager-toolkit
Pass
Audited by Gen Agent Trust Hub on Jun 19, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill is a set of informational templates and local analytical tools with no malicious behavior identified. All scripts operate within the local execution environment on user-provided data.\n- [PROMPT_INJECTION]: No attempts to bypass safety filters, override system instructions, or extract sensitive prompt data were detected in any files.\n- [DATA_EXPOSURE_AND_EXFILTRATION]: No access to sensitive file paths (e.g., .ssh, .aws) or credentials. The scripts do not perform network operations, ensuring data remains local.\n- [REMOTE_CODE_EXECUTION]: The toolkit relies on scripts that use only standard Python libraries. There are no patterns of downloading and executing remote code or piping network data to a shell.\n- [DYNAMIC_EXECUTION]: No use of dynamic execution functions such as eval() or exec(). The provided logic is deterministic and restricted to parsing text and calculating scores.\n- [INDIRECT_PROMPT_INJECTION]: While the skill ingests external data (transcripts and CSVs), it represents a safe surface. The scripts only perform metadata extraction and scoring without triggering dangerous capabilities like network access or system modification.
Audit Metadata