milestone-workflow
Pass
Audited by Gen Agent Trust Hub on Jul 30, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill processes untrusted external data from repository artifacts, which could contain malicious instructions.
- Ingestion points: Reads repository instructions, milestone, roadmap, task, backlog, and issue artifacts as described in SKILL.md.
- Boundary markers: Absent; the instructions do not require the use of delimiters or 'ignore' directives when processing content from external files.
- Capability inventory: The skill coordinates several other atomic skills, such as task-execution-simple and technical-design, which may perform modifications or execute code.
- Sanitization: Absent; the instructions do not specify any validation or filtering for the data ingested from the repository.
Audit Metadata