to-proposal
Pass
Audited by Gen Agent Trust Hub on Aug 14, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill consists of instructional text and a proposal template. It does not contain any executable code, scripts, or obfuscated payloads.
- [INDIRECT_PROMPT_INJECTION]: The skill's primary function is to ingest conversation history, which is considered untrusted data. However, the skill explicitly mandates a 'Confirm, then publish' step, ensuring the user reviews the generated output before it is sent to external trackers (GitHub or Linear). This effectively mitigates the risk of an agent acting on hidden instructions within the conversation history.
- [DATA_EXFILTRATION]: While the skill mentions publishing to GitHub and Linear, these are identified as well-known developer services and the skill requires explicit user approval ('Never publish without approval') before performing these actions. No automated exfiltration to unknown or malicious domains was detected.
Audit Metadata