pm-skills

Pass

Audited by Gen Agent Trust Hub on Sep 3, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill suite possesses a significant attack surface for indirect prompt injection through its ingestion of external data. \n
  • Ingestion points: Data is ingested from various external sources in multiple files: meeting-analyzer/SKILL.md scans and parses transcript files (.docx, .srt, .vtt, .json, .txt); team-communications/SKILL.md gathers data from Slack, Gmail, Google Drive, and Calendar; and all 12 Python scripts process external data from JSON exports. \n
  • Boundary markers: The skill instructions do not define clear delimiters (such as XML tags or triple quotes) or provide specific directives for the agent to treat ingested data as untrusted or to ignore embedded instructions. \n
  • Capability inventory: The suite is integrated with the Atlassian MCP Server, giving the agent capabilities to perform sensitive operations like creating and updating Jira issues and Confluence pages based on the ingested content. \n
  • Sanitization: There is no evidence of sanitization, filtering, or validation of the external content before it is interpolated into the agent's context.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 3, 2026, 02:34 PM
Security Audit — agent-trust-hub — pm-skills