suggest-projects
Pass
Audited by Gen Agent Trust Hub on Apr 29, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: Restricted command execution. The skill is limited to using basic bash commands like mkdir, test, and date, which prevents any high-risk system operations or privilege escalation attempts.
- [SAFE]: Legitimate data operations. The skill reads local context files and writes its recommendations to a designated local folder. There are no signs of hardcoded credentials or unauthorized network exfiltration.
- [SAFE]: Indirect prompt injection analysis. While the skill ingests external content from company briefs and domain notes, its restricted toolset (limited bash and local writing) prevents exploitation.
- Ingestion points: ground-truth.md, skills note, company briefs, and domain notes.
- Boundary markers: Not explicitly implemented.
- Capability inventory: File reading/writing, web search, and restricted bash (mkdir/test/date).
- Sanitization: Not explicitly implemented.
Audit Metadata