pm-product-review
Pass
Audited by Gen Agent Trust Hub on Jun 22, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill acts as a task router and report aggregator for PM documents such as PRDs, OKRs, and roadmaps. No dangerous patterns were identified within the instructional logic.
- [DATA_EXFILTRATION]: No network operations or sensitive file path accesses were found. The skill operates entirely within the established agent context using user-provided project data.
- [PROMPT_INJECTION]: The instructions do not contain attempts to override AI safety guidelines, jailbreak the model, or extract internal system prompts.
- [REMOTE_CODE_EXECUTION]: The skill does not download or execute external scripts, nor does it install unverified packages. It references other internal skills (e.g., pm-spec-quality-audit) which are part of the local environment.
Audit Metadata