project-crank-engine

Pass

Audited by Gen Agent Trust Hub on Sep 4, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses several Git and GitHub CLI commands (git rev-parse, git log, git status, git stash, gh pr list) to gather project status evidence. These are standard development tools and are used here for monitoring purposes.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external data from sprint boards and GitHub PRs to determine project completion. It lacks explicit boundary markers or sanitization for this untrusted data before it is interpolated into decision-making prompts.
  • Ingestion points: External sprint board metrics and GitHub PR states are ingested via {{done_metric_query}} and command outputs in references/prompt-templates.md.
  • Boundary markers: None identified in the prompt templates to distinguish between instructions and ingested data.
  • Capability inventory: The skill uses subprocess (via scripts/render_crank_prompt.py) and shell commands for repo/sprint status checks.
  • Sanitization: No explicit sanitization or validation of the ingested strings from the sprint board or GitHub API is present.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 4, 2026, 06:55 AM
Security Audit — agent-trust-hub — project-crank-engine