project-manager

Pass

Audited by Gen Agent Trust Hub on May 1, 2026

Risk Level: SAFE
Full Analysis
  • [DYNAMIC_CONTEXT_INJECTION]: The SKILL.md file utilizes dynamic context injection (!cat) to load internal protocol and configuration files. This is a benign use for environment setup and does not incorporate untrusted user input.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process data from external project management tools (e.g., Jira issue descriptions, Linear tasks). The implementation includes sanitization logic in tests/async-standup.test.ts to filter potentially malicious HTML tags and JavaScript protocols, mitigating common injection vectors.
  • [EXTERNAL_DOWNLOADS]: The documentation and setup guides reference well-known, official packages from trusted vendors (e.g., @linear/mcp, @modelcontextprotocol/server-github, and @atlassian/rovo-dev). These are standard dependencies for the claimed functionality.
  • [COMMAND_EXECUTION]: The skill includes a local Python utility (excel-generator/generator_app.py) for generating project planning Excel files. Analysis of the script confirms it performs legitimate data processing using the openpyxl library without executing arbitrary shell commands or performing unauthorized network operations.
Audit Metadata
Risk Level
SAFE
Analyzed
May 1, 2026, 08:02 AM
Security Audit — agent-trust-hub — project-manager