progress-tracking
Pass
Audited by Gen Agent Trust Hub on Jul 13, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill defines a methodical workflow for managing task lifecycles and status reporting. It leverages platform-provided tools like todowrite and agentmemory to maintain session state correctly.
- [COMMAND_EXECUTION]: Uses the built-in todowrite tool for task management and suggests checking git history and local files to reconstruct state in SKILL.md. These actions are within the scope of a development-oriented agent and do not include arbitrary shell execution.
- [DATA_EXFILTRATION]: Stores task metadata in .opencode/memory/task-status.json and agent memory as described in SKILL.md. Access is limited to internal state tracking and does not involve exfiltrating user secrets or sensitive documents.
- [PROMPT_INJECTION]: Identifies an indirect prompt injection surface during state reconstruction from the codebase. Ingestion points: Analyzes git history, modified files, and agentmemory as described in SKILL.md to infer progress. Boundary markers: Missing specific delimiters for data retrieved from external sources. Capability inventory: Updates internal task lists via todowrite and memory_save as described in SKILL.md. Sanitization: No explicit sanitization or validation of external data before processing. Assessment: The surface is associated with the intended primary skill purpose of task tracking, resulting in a safe assessment for this context.
Audit Metadata