specialist-product-sprint-prioritizer

Pass

Audited by Gen Agent Trust Hub on Aug 15, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill consists of purely instructional content designed to assist with product management tasks. All included frameworks (RICE, Kano, MoSCoW) are standard business practices and the behavior matches the skill's stated purpose.
  • [PROMPT_INJECTION]: The skill interpolates user input directly into a subagent's system prompt, which presents a surface for indirect prompt injection.
  • Ingestion points: Untrusted data enters the agent context through the {the_user_question} variable in SKILL.md.
  • Boundary markers: Absent; the user input is appended to the instructions without delimiters or protective framing.
  • Capability inventory: The subagent instructions do not provide access to sensitive tools, file system operations, or network commands.
  • Sanitization: No filtering or sanitization of the user input is performed prior to interpolation.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 15, 2026, 08:50 PM
Security Audit — agent-trust-hub — specialist-product-sprint-prioritizer