product-skills

Pass

Audited by Gen Agent Trust Hub on May 14, 2026

Risk Level: SAFE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted external content such as customer interview transcripts, research papers, and project source code for analysis. While no immediate exploit was found, this creates a surface for indirect prompt injection. Ingestion points are located in product-manager-toolkit/SKILL.md, research-summarizer/SKILL.md, and code-to-prd/SKILL.md. The skill possesses capabilities for file system modification and script execution.
  • [DYNAMIC_EXECUTION]: Modules like spec-to-repo and saas-scaffolder generate functional source code and directory structures from natural language requirements. This is the intended purpose of these tools and relies on established templates.
Audit Metadata
Risk Level
SAFE
Analyzed
May 14, 2026, 01:10 PM
Security Audit — agent-trust-hub — product-skills