pm-product-canvas

Pass

Audited by Gen Agent Trust Hub on Jul 19, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: Comprehensive analysis of the skill's instructions and structure reveals no patterns of prompt injection, obfuscation, or credential theft.
  • [SAFE]: The skill uses local file references (e.g., ../pm-copilot/references/framework.md) appropriately for project context and does not engage in any unauthorized network exfiltration or sensitive file access.
  • [SAFE]: Indirect Prompt Injection: The skill ingests untrusted user data through structured interviews and reads external dossiers (referenced in SKILL.md). Boundary markers and sanitization steps are absent; however, the skill's capabilities (Bash, Write, Edit) are employed only for the legitimate purpose of generating business case artifacts, presenting an acceptable risk profile for this use case.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 19, 2026, 05:16 PM
Security Audit — agent-trust-hub — pm-product-canvas