product-management
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted user-provided data such as customer feedback and founder notes which could potentially contain malicious instructions. Ingestion points: Processing of customer inputs mentioned in SKILL.md and scripts/product_scorer.py which reads JSON feature backlogs. Capability inventory: The skill can read local files and execute Python scripts. Boundary markers: The skill does not provide clear delimiters or specific instructions for the agent to ignore potentially embedded commands in the user data. Sanitization: No explicit data sanitization or validation beyond standard JSON parsing is specified.
- [COMMAND_EXECUTION]: The skill provides a Python script scripts/product_scorer.py and instructs its use via CLI for scoring features. The script uses only the standard library and operates locally on data files without network connectivity or dynamic code execution of input values.
Audit Metadata