skills/77hub/cli-skills/qiqi-project/Gen Agent Trust Hub

qiqi-project

Pass

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes data ingested from external CLI tool outputs and project records, which represents a potential attack surface for indirect prompt injection.
  • Ingestion points: Data is retrieved through commands like objects, seek, query list, and records get as specified in SKILL.md.
  • Boundary markers: The instructions do not define explicit delimiters or instructions to ignore potential commands embedded within project or task names.
  • Capability inventory: The skill has functional write capabilities including project task create, project task update, and project work-hours log (as listed in SKILL.md).
  • Sanitization: Although the skill mandates the use of structured JSON for --data and checking --help for field definitions, it lacks specific sanitization logic for content originating from external records.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 21, 2026, 07:54 AM
Security Audit — agent-trust-hub — qiqi-project