pm-copilot

Pass

Audited by Gen Agent Trust Hub on Jul 19, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses shell access to manage project folders and generate documents. It explicitly instructs the agent to 'slugify' feature and folder names, which serves as a security best practice to prevent command injection or path traversal when creating local files based on user input.- [DATA_EXFILTRATION]: The skill's operations are confined to the local working directory and the specific project dossier. There are no network operations, and the skill does not attempt to access sensitive system files or credentials.- [PROMPT_INJECTION]: The instructions are focused on guiding the user through a professional product management framework. No attempts to bypass safety filters, override system instructions, or extract underlying system prompts were detected.- [SAFE]: The skill provides a structured and legitimate workflow for product management. It includes clear instructions for handling project state, resuming work from previous sessions, and ensuring that document generation is handled transparently with the user.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 19, 2026, 05:16 PM
Security Audit — agent-trust-hub — pm-copilot