premortem
Pass
Audited by Gen Agent Trust Hub on Jul 17, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The skill uses system shell commands (
xdg-open,open, andstart) to automatically launch the generated HTML report in the user's default browser or viewer. - [PROMPT_INJECTION]: The skill ingests untrusted data from the local workspace (e.g.,
CLAUDE.md,memory/folders, andsrd/project files) to ground its analysis. This content is passed to sub-agents without explicit sanitization, which could lead to indirect prompt injection if the files contain malicious instructions. - Ingestion points: Local workspace files including
CLAUDE.md,memory/directories, and Linear-relatedsrd/folders. - Boundary markers: None identified in the prompt template used for sub-agents.
- Capability inventory: The skill can spawn new sub-agents using the
Agenttool and execute local shell commands to open files. - Sanitization: The skill does not perform escaping or filtering of the workspace content before interpolating it into prompts.
- [EXTERNAL_DOWNLOADS]: The skill's documentation provides links to third-party GitHub repositories (
expectedparrot/premortemandiepathos/premortem) referenced as prior art.
Audit Metadata