project-next-step
Pass
Audited by Gen Agent Trust Hub on Jul 24, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [SAFE]: The skill focuses on analytical tasks and documentation within the project workspace, showing no signs of malicious intent or dangerous capabilities.
- [COMMAND_EXECUTION]: The instructions involve checking Git status and project files to establish current facts, which is standard behavior for development-oriented agents.
- [PROMPT_INJECTION]: The skill processes untrusted data sources which could theoretically contain malicious instructions (Indirect Prompt Injection).
- Ingestion points:
SKILL.md(Step 2: user/run feedback, existing project documents, Roadmap). - Boundary markers: Absent.
- Capability inventory: Reading local project files and writing decision logs to the
workplace/directory. - Sanitization: No explicit sanitization or validation of the ingested project data is described.
Audit Metadata