to-backlog
Pass
Audited by Gen Agent Trust Hub on Jul 29, 2026
Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [PROMPT_INJECTION]: The skill exhibits an attack surface for indirect prompt injection by processing untrusted user input from conversation history to generate backlog items and update wiki pages. Ingestion points: conversation-confirmed work items (Step 1). Boundary markers: absent. Capability inventory: write access to backlog and wiki directories, and execution of a local validation script. Sanitization: none mentioned.
- [COMMAND_EXECUTION]: The skill executes
node scripts/validate-project.mjsas part of the reporting phase to verify project integrity. This is a standard project management function.
Audit Metadata