digidai-pm

Warn

Audited by Gen Agent Trust Hub on Jun 13, 2026

Risk Level: MEDIUMEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONREMOTE_CODE_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill is configured to download its full content from an external GitHub repository (github.com/Digidai/product-manager-skills) which is not a pre-verified source.
  • [COMMAND_EXECUTION]: The instructions direct the agent to execute shell commands using grep to check local file paths for installation status.
  • [REMOTE_CODE_EXECUTION]: The skill uses the npx skills add command to fetch and install logic from a remote repository, introducing unverified code into the agent's environment.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Jun 13, 2026, 10:45 AM
Security Audit — agent-trust-hub — digidai-pm