weekly
Pass
Audited by Gen Agent Trust Hub on Aug 30, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes a local script located at
tools/open_loops.pyto retrieve task statuses. This execution is part of the skill's primary function and does not involve remote downloads or arbitrary command injection from external sources. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest data from local project files, creating a potential surface for processing untrusted content if those files are compromised. However, the risk is managed as the sources are internal project documents, and the skill includes instructions for evidence-based assessment.
- Ingestion points:
context/priorities.md,decisions/log.md, and theprojects/directory. - Boundary markers: Not present.
- Capability inventory: Local subprocess execution of
tools/open_loops.pyand file-write access todecisions/log.md. - Sanitization: Instructions mandate "evidence over assertion" and specify that no confidential figures should be persisted, directing the agent to reference live sources instead.
Audit Metadata