product-owner

Pass

Audited by Gen Agent Trust Hub on Aug 18, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill uses directive instructions like 'High Decision Weight' and 'overrides feature enthusiasm' to establish a specific behavioral persona. While intended for its functional role, this uses command patterns that instruct the agent to disregard certain types of user or contextual input.
  • [PROMPT_INJECTION]: The skill has a significant attack surface for indirect prompt injection due to its reliance on external data sources for core decision logic.
  • Ingestion points: Reads project files (AGENTS.md, ROADMAP.md, CONTEXT.md) and user-provided artifacts (Jira tickets).
  • Boundary markers: There are no explicit instructions to use delimiters or to treat the ingested data as untrusted content.
  • Capability inventory: The skill routes the agent to sensitive development and architecture tasks based on the evaluation of external data.
  • Sanitization: The instructions do not include any steps for sanitizing or validating the content read from external files before processing it.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 18, 2026, 12:28 PM
Security Audit — agent-trust-hub — product-owner