ops-projects
Pass
Audited by Gen Agent Trust Hub on Oct 8, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests data from external project files to populate the dashboard, creating a surface for indirect prompt injection.
- Ingestion points: Files located in
~/Projects/and~/gsd-workspaces/under.planning/directories, specificallyHANDOFF.json,STATE.md,ROADMAP.md, andMILESTONES.md(referenced in SKILL.md). - Boundary markers: None are defined; the skill directly interpolates values like
next_actiontext and milestone names into the dashboard output without delimitation. - Capability inventory: The skill has access to
Bashfor command execution,Readfor file access, andWebFetchfor network operations. - Sanitization: There is no mention of sanitizing or escaping the text read from project files before it is processed by the agent.
- [COMMAND_EXECUTION]: The skill executes a shell script for synchronization tasks.
- Evidence: The command
bash ${CLAUDE_PLUGIN_ROOT}/scripts/ops-gsd-registry-sync.shis executed when the user provides the--syncor--refresharguments. This is a local execution of a script provided by the plugin environment.
Audit Metadata