project-development-review-v3

Pass

Audited by Gen Agent Trust Hub on Jul 4, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection because it processes untrusted external data to verify R&D progress.
  • Ingestion points: The agent is instructed to read from user-provided file paths, direct upstream entries, support materials, and "real code" or project evidence to verify claims (SKILL.md, Execution Steps 1 and 3).
  • Boundary markers: The skill lacks instructions for the agent to treat external data as untrusted or to ignore instructions embedded within the ingested materials.
  • Capability inventory: The skill possesses the capability to read local project files and write back to the filesystem to create review reports and update links within the entry documents (SKILL.md, Storage and Path Contract).
  • Sanitization: There is no defined process for sanitizing, escaping, or validating the content of the external files before the agent processes them or includes them in its final reporting.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 4, 2026, 01:27 PM
Security Audit — agent-trust-hub — project-development-review-v3