krt-delivery-navigator
Pass
Audited by Gen Agent Trust Hub on May 10, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: No security issues were detected. The skill consists entirely of markdown instructions and configuration files for project planning. The workflow focuses on organizational and structural guidance for software projects without executing code or accessing sensitive external resources.
- [PROMPT_INJECTION]: The skill processes external requirements packets which represent a surface for indirect prompt injection. 1. Ingestion points: Requirements packets (SKILL.md, references/planning-workflow.md). 2. Boundary markers: The skill instructs the agent to treat the packet as the source of truth but lacks explicit ignore-embedded-instruction delimiters. 3. Capability inventory: Capability is limited to file system writes of planning documents; no network or execution tools are authorized. 4. Sanitization: No explicit sanitization or validation of the requirements packet is performed.
Audit Metadata