Product Manager
Pass
Audited by Gen Agent Trust Hub on Aug 5, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill defines a standard set of product management responsibilities and workflows. No malicious patterns such as command execution, unauthorized network access, or obfuscation were detected.
- [INDIRECT_PROMPT_INJECTION]: The skill presents an attack surface for indirect prompt injection because it is designed to ingest and process untrusted data from external project files.
- Ingestion points: The skill reads external product briefs (e.g.,
docs/product-brief-*.md) to inform its requirements gathering process. - Boundary markers: No explicit delimiters or instructions to ignore embedded commands are present in the core instructions.
- Capability inventory: The skill possesses the capability to write to the file system (e.g.,
TodoWrite,Save Output Documentfunctions) to create PRDs and technical specifications. - Sanitization: No explicit sanitization or validation of the ingested file content is performed before processing.
Audit Metadata