github-roadmap-strategist
Pass
Audited by Gen Agent Trust Hub on Apr 19, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill is primarily instructional, defining project management workflows and field taxonomies for GitHub Projects V2 without executing arbitrary code.
- [SAFE]: The documentation includes security-focused advice, specifically the 'Shadow Item' pattern in references/governance-protocols.md, which details how to sanitize and manually review content before moving it from private to public environments to avoid permission leaks.
- [SAFE]: The skill establishes an ingestion surface for untrusted data via GitHub Issues and repository metadata as described in SKILL.md. To mitigate indirect prompt injection risks, it provides explicit sanitization guidelines and manual review protocols within the Shadow Item pattern (documented in references/governance-protocols.md). The skill maintains a restricted capability inventory focused on project management API calls and GitHub Action triggers, and while it lacks formal prompt delimiters (boundary markers), the operational procedures are designed to prevent accidental instruction obedience.
- [SAFE]: GitHub Action templates provided in the reference material use standard, well-known actions and triggers for routine automation tasks like stale item cleanup and status updates.
Audit Metadata