timetracker
Pass
Audited by Gen Agent Trust Hub on Aug 14, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill processes untrusted external data from project artifacts, creating a surface for indirect prompt injection.\n
- Ingestion points: The skill reads various project-related files during discovery, including plans, decisions, meetings, site-reports, TASKS.md, and PROJECT.md as instructed in SKILL.md.\n
- Boundary markers: The instructions lack explicit delimiters or specific warnings to ignore embedded instructions within these artifacts.\n
- Capability inventory: The agent is granted access to Write, Edit, and Bash tools (defined in SKILL.md), which could potentially be exploited if the agent executes instructions found in the processed files.\n
- Sanitization: No sanitization, filtering, or escaping of the content extracted from external artifacts is mentioned in the skill instructions.
Audit Metadata