Product Manager

Pass

Audited by Gen Agent Trust Hub on Aug 5, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill defines a standard set of product management responsibilities and workflows. No malicious patterns such as command execution, unauthorized network access, or obfuscation were detected.
  • [INDIRECT_PROMPT_INJECTION]: The skill presents an attack surface for indirect prompt injection because it is designed to ingest and process untrusted data from external project files.
  • Ingestion points: The skill reads external product briefs (e.g., docs/product-brief-*.md) to inform its requirements gathering process.
  • Boundary markers: No explicit delimiters or instructions to ignore embedded commands are present in the core instructions.
  • Capability inventory: The skill possesses the capability to write to the file system (e.g., TodoWrite, Save Output Document functions) to create PRDs and technical specifications.
  • Sanitization: No explicit sanitization or validation of the ingested file content is performed before processing.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 5, 2026, 04:49 PM
Security Audit — agent-trust-hub — Product Manager