project-next-step

Pass

Audited by Gen Agent Trust Hub on Jul 24, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill focuses on analytical tasks and documentation within the project workspace, showing no signs of malicious intent or dangerous capabilities.
  • [COMMAND_EXECUTION]: The instructions involve checking Git status and project files to establish current facts, which is standard behavior for development-oriented agents.
  • [PROMPT_INJECTION]: The skill processes untrusted data sources which could theoretically contain malicious instructions (Indirect Prompt Injection).
  • Ingestion points: SKILL.md (Step 2: user/run feedback, existing project documents, Roadmap).
  • Boundary markers: Absent.
  • Capability inventory: Reading local project files and writing decision logs to the workplace/ directory.
  • Sanitization: No explicit sanitization or validation of the ingested project data is described.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 24, 2026, 08:51 AM
Security Audit — agent-trust-hub — project-next-step