knowledge-status-report
Pass
Audited by Gen Agent Trust Hub on Jun 14, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill is designed exclusively for read-only analysis of local project files (Markdown and YAML) to generate status reports. It includes explicit guardrails preventing any modification of files, Kanban boards, or metadata.
- [COMMAND_EXECUTION]: The skill mentions using git history for activity reporting. This is a legitimate, context-appropriate use of developer tools for status reporting and does not involve arbitrary or dangerous command execution.
- [DATA_EXPOSURE]: While the skill reads project configuration files such as manifest.yml and runtime.md, these are used solely to resolve paths and identify knowledge areas within the repository. There is no evidence of sensitive data exposure or network exfiltration.
- [PROMPT_INJECTION]: No evidence of prompt injection or behavior override patterns was detected. The instructions are task-oriented and emphasize maintaining a separation between factual data and inference.
Audit Metadata