skill-spec-product
Pass
Audited by Gen Agent Trust Hub on May 13, 2026
Risk Level: SAFENO_CODE
Full Analysis
- [NO_CODE]: The skill consists entirely of Markdown documentation and YAML templates defining a Product Spec-Driven Delivery framework. No executable scripts (Python, JavaScript, Shell) or binaries are present in the package.
- [SAFE]: The framework instructions guide the AI agent and product managers through discovery, prioritization, and handoff phases. All external links point to legitimate, well-known productivity tools (such as Figma, Miro, and Linear) or educational resources.
- [PROMPT_INJECTION]: There are no attempts to override agent behavior, bypass safety guardrails, or extract system prompts. The instructions are focused on structured data collection and product management best practices.
- [EXTERNAL_DOWNLOADS]: Mentions of external tools and validation libraries (like
yamllintandSpectral) are provided as informational references for the user and do not involve the automated download or execution of untrusted remote content. - [DATA_EXFILTRATION]: No patterns for unauthorized access to sensitive local files (e.g., credentials, environment variables) or network exfiltration were found. The skill operates within the scope of user-provided product requirements.
Audit Metadata