skill-spec-product

Pass

Audited by Gen Agent Trust Hub on May 13, 2026

Risk Level: SAFENO_CODE
Full Analysis
  • [NO_CODE]: The skill consists entirely of Markdown documentation and YAML templates defining a Product Spec-Driven Delivery framework. No executable scripts (Python, JavaScript, Shell) or binaries are present in the package.
  • [SAFE]: The framework instructions guide the AI agent and product managers through discovery, prioritization, and handoff phases. All external links point to legitimate, well-known productivity tools (such as Figma, Miro, and Linear) or educational resources.
  • [PROMPT_INJECTION]: There are no attempts to override agent behavior, bypass safety guardrails, or extract system prompts. The instructions are focused on structured data collection and product management best practices.
  • [EXTERNAL_DOWNLOADS]: Mentions of external tools and validation libraries (like yamllint and Spectral) are provided as informational references for the user and do not involve the automated download or execution of untrusted remote content.
  • [DATA_EXFILTRATION]: No patterns for unauthorized access to sensitive local files (e.g., credentials, environment variables) or network exfiltration were found. The skill operates within the scope of user-provided product requirements.
Audit Metadata
Risk Level
SAFE
Analyzed
May 13, 2026, 09:31 AM