pm-discovery
Pass
Audited by Gen Agent Trust Hub on May 16, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill possesses a surface for indirect prompt injection by processing untrusted data.
- Ingestion points: User-provided
{feature}argument and PRD files read from thedocs/00-pm/directory. - Boundary markers: None present in the skill instructions to delimit untrusted content.
- Capability inventory: The skill has access to
Read,Write,Edit,Glob,Grep, andBashtools as defined in theSKILL.mdfrontmatter. - Sanitization: There is no evidence of input validation or content sanitization for the feature names or ingested documents.
- [DATA_EXFILTRATION]: The skill is configured to read and write product documentation within the project's subdirectories. No patterns suggesting unauthorized access to sensitive system files or credentials were detected.
- [EXTERNAL_DOWNLOADS]: The skill provides an informational link to a GitHub repository for methodological credit. This is a reference to a well-known service and does not trigger remote code execution.
Audit Metadata