product-manager
Pass
Audited by Gen Agent Trust Hub on Aug 15, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill instructions define a structured workflow for product management tasks, focusing on requirements gathering, user stories, and acceptance criteria.
- [DATA_EXPOSURE]: The skill accesses project-specific directories and memory files located within
~/.ai-software-agency/. These paths are consistent with the skill's operational context and do not attempt to access sensitive system-level credentials such as SSH keys or cloud provider configurations. - [INDIRECT_PROMPT_INJECTION]: The skill ingests data from external sources including a goal brief and user-provided answers to clarifying questions. While this creates a surface for indirect prompt injection, it is managed through a documented governance process. \n
- Ingestion points: Discovery Phase (goal brief, goals.md, and user answers) and specialist output files. \n
- Boundary markers: Absent. \n
- Capability inventory:
Write,Edit,TaskCreate, andAgent(sub-agent spawning) capabilities across the workflow. \n - Sanitization: None explicitly stated; however, the workflow mandates a manual approval gate (
GATE_READYto CEO) before completion, providing human-in-the-loop oversight.
Audit Metadata