premortem

Pass

Audited by Gen Agent Trust Hub on Jul 17, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses system shell commands (xdg-open, open, and start) to automatically launch the generated HTML report in the user's default browser or viewer.
  • [PROMPT_INJECTION]: The skill ingests untrusted data from the local workspace (e.g., CLAUDE.md, memory/ folders, and srd/ project files) to ground its analysis. This content is passed to sub-agents without explicit sanitization, which could lead to indirect prompt injection if the files contain malicious instructions.
  • Ingestion points: Local workspace files including CLAUDE.md, memory/ directories, and Linear-related srd/ folders.
  • Boundary markers: None identified in the prompt template used for sub-agents.
  • Capability inventory: The skill can spawn new sub-agents using the Agent tool and execute local shell commands to open files.
  • Sanitization: The skill does not perform escaping or filtering of the workspace content before interpolating it into prompts.
  • [EXTERNAL_DOWNLOADS]: The skill's documentation provides links to third-party GitHub repositories (expectedparrot/premortem and iepathos/premortem) referenced as prior art.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 17, 2026, 12:16 AM