pm-prioritization-rigor-audit
Pass
Audited by Gen Agent Trust Hub on Jun 22, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [SAFE]: The skill contains only natural language instructions and lacks executable scripts, shell commands, or automated file system modifications.
- [EXTERNAL_DOWNLOADS]: The skill provides links to several educational lessons on the Uxcel website (
uxcel.com). These are informational references to the author's official documentation and are not used for runtime code execution or software installation. - [PROMPT_INJECTION]: The skill utilizes directive language to steer agent behavior (e.g., "This audit forces four things"). These are standard prompt engineering techniques intended to align the model with its specialized auditing role rather than bypass safety guidelines.
- [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface as it is designed to ingest and process untrusted prioritization data provided by users. However, since the skill has no access to sensitive capabilities like network operations or command execution, this surface does not present a security risk.
- Ingestion points: User-supplied prioritization lists, scoring tables, and backlog data processed in
SKILL.md. - Boundary markers: Absent.
- Capability inventory: No file system access, network operations, or shell execution capabilities found in the skill content.
- Sanitization: Absent.
Audit Metadata