product-metrics

Pass

Audited by Gen Agent Trust Hub on Aug 29, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill mentions installation commands for related tools using npx skills add pedroromeroluna/ai-first-product-skills. These resources are provided by the skill's author and belong to the same product suite.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes data from local files, specifically Discovery Briefs generated by other components. While this is a data ingestion surface, the skill uses it to extract hypotheses for an interview process and does not grant elevated privileges or execute code based on that input.
  • [COMMAND_EXECUTION]: The instructions involve writing research files to the local file system (e.g., research/YYYY-MM-DD-metric-brief.md). This is the primary intended function of the skill and is handled within the scope of documented product management workflows.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 29, 2026, 05:22 AM
Security Audit — agent-trust-hub — product-metrics