pm-plan-requirements-brief
Pass
Audited by Gen Agent Trust Hub on Apr 14, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill defines a text-based workflow for project management. Analysis of the instructions and evaluation criteria shows no attempts at prompt injection, unauthorized data access, or obfuscation.
- [PROMPT_INJECTION]: The skill involves processing potentially untrusted data from stakeholder notes and tickets, which represents an indirect prompt injection surface.
- Ingestion points: Stakeholder notes, requirement documents, and support tickets mentioned in SKILL.md.
- Boundary markers: Not explicitly defined in the workflow steps.
- Capability inventory: The skill is limited to generating text reports and does not reference any tools capable of file system modification, network communication, or code execution.
- Sanitization: No specific input sanitization or validation logic is present.
- [DATA_EXPOSURE]: The skill references
.agents/project-context.mdfor project context. This is a standard practice for project-aware agents and is limited to the local project environment.
Audit Metadata