program-manager

Pass

Audited by Gen Agent Trust Hub on Sep 28, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides legitimate program management capabilities through a structured framework and local analytical tools. Its core functions—governance design, charter creation, dependency mapping, and resource planning—are implemented through markdown guides and Python scripts that perform deterministic calculations.
  • [COMMAND_EXECUTION]: The skill instructions in SKILL.md and the references/ directory guide the user to execute local Python scripts (scripts/milestone_tracker.py, scripts/portfolio_dashboard.py, scripts/resource_allocator.py) to process project data. Analysis of these scripts confirms they use standard libraries (argparse, json, datetime) to perform data analysis and reporting. They do not contain any patterns for network communication, sensitive file access, or remote code execution.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external data related to project milestones and resource allocations, which represents a potential surface for indirect prompt injection if the source data is untrusted.
  • Ingestion points: Data is ingested through JSON and YAML files (e.g., milestones.json, portfolio.json, projects.yaml) as specified in the script usage examples and skill documentation.
  • Boundary markers: No specific delimiters or boundary markers are defined in the instructions to separate untrusted data from agent instructions.
  • Capability inventory: The skill's scripts are limited to numeric and date-based calculations (e.g., critical path slack, budget variance, FTE utilization). No capabilities for file system modification, network operations, or dynamic code execution (eval/exec) were found.
  • Sanitization: The scripts perform validation on structured data types (dates and numbers) but do not apply specific sanitization to descriptive string fields. The structured nature of the script outputs (tables and reports) minimizes the risk of the agent misinterpreting data as instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 28, 2026, 07:29 AM
Security Audit — agent-trust-hub — program-manager