skills/coleam00/skills/piv-slice-epic/Gen Agent Trust Hub

piv-slice-epic

Pass

Audited by Gen Agent Trust Hub on Aug 7, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it reads and processes external documents from URLs and local paths to generate task descriptions. It lacks explicit boundary markers or sanitization instructions to prevent the agent from following malicious commands that might be embedded in the input epic or architecture documents.
  • [DATA_EXPOSURE]: The skill possesses the capability to read local codebase files and project documentation, summarizing this information to create tickets in external tracking platforms like Jira, Linear, and GitHub. This data movement is the primary intended function of the skill, but users should be aware that codebase metadata is being shared with their configured external services.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 7, 2026, 04:27 PM
Security Audit — agent-trust-hub — piv-slice-epic