project-manager
Pass
Audited by Gen Agent Trust Hub on May 1, 2026
Risk Level: SAFE
Full Analysis
- [DYNAMIC_CONTEXT_INJECTION]: The
SKILL.mdfile utilizes dynamic context injection (!cat) to load internal protocol and configuration files. This is a benign use for environment setup and does not incorporate untrusted user input. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process data from external project management tools (e.g., Jira issue descriptions, Linear tasks). The implementation includes sanitization logic in
tests/async-standup.test.tsto filter potentially malicious HTML tags and JavaScript protocols, mitigating common injection vectors. - [EXTERNAL_DOWNLOADS]: The documentation and setup guides reference well-known, official packages from trusted vendors (e.g.,
@linear/mcp,@modelcontextprotocol/server-github, and@atlassian/rovo-dev). These are standard dependencies for the claimed functionality. - [COMMAND_EXECUTION]: The skill includes a local Python utility (
excel-generator/generator_app.py) for generating project planning Excel files. Analysis of the script confirms it performs legitimate data processing using theopenpyxllibrary without executing arbitrary shell commands or performing unauthorized network operations.
Audit Metadata