NYC

product-manager-toolkit

Pass

Audited by Gen Agent Trust Hub on Feb 17, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [Indirect Prompt Injection] (LOW): The skill includes scripts that process external files which could contain untrusted instructions. Evidence Chain: 1. Ingestion points: interview_transcript.txt and features.csv. 2. Boundary markers: None identified. 3. Capability inventory: Local Python execution of scripts/rice_prioritizer.py and scripts/customer_interview_analyzer.py. 4. Sanitization: No input validation is mentioned.
  • [Remote Code Execution] (SAFE): No remote downloads or suspicious execution patterns were found.
  • [Data Exposure] (SAFE): No sensitive files or credentials are hardcoded or accessed.
Audit Metadata
Risk Level
SAFE
Analyzed
Feb 17, 2026, 06:30 PM