create-project

Pass

Audited by Gen Agent Trust Hub on Aug 16, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [SAFE]: The skill facilitates local project management through structured CSV updates. No malicious patterns, obfuscation, or unauthorized data access attempts were identified.
  • [COMMAND_EXECUTION]: The Python code snippets provided use the pandas and uuid libraries to append new project and task entries to local CSV files. These operations are restricted to the path specified by the $PM_PATH environment variable.
  • [INDIRECT_PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface. Ingestion points: User-provided strings for project names and descriptions interpolated into Python scripts. Boundary markers: None (absent). Capability inventory: Local file write access via the pandas.to_csv tool. Sanitization: None (absent). While the skill lacks sanitization, the risk is assessed as safe as it only affects local structured data.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 16, 2026, 02:15 AM
Security Audit — agent-trust-hub — create-project