product-manager

Pass

Audited by Gen Agent Trust Hub on Aug 15, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill instructions define a structured workflow for product management tasks, focusing on requirements gathering, user stories, and acceptance criteria.
  • [DATA_EXPOSURE]: The skill accesses project-specific directories and memory files located within ~/.ai-software-agency/. These paths are consistent with the skill's operational context and do not attempt to access sensitive system-level credentials such as SSH keys or cloud provider configurations.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests data from external sources including a goal brief and user-provided answers to clarifying questions. While this creates a surface for indirect prompt injection, it is managed through a documented governance process. \n
  • Ingestion points: Discovery Phase (goal brief, goals.md, and user answers) and specialist output files. \n
  • Boundary markers: Absent. \n
  • Capability inventory: Write, Edit, TaskCreate, and Agent (sub-agent spawning) capabilities across the workflow. \n
  • Sanitization: None explicitly stated; however, the workflow mandates a manual approval gate (GATE_READY to CEO) before completion, providing human-in-the-loop oversight.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 15, 2026, 08:49 PM
Security Audit — agent-trust-hub — product-manager