project-ops

Pass

Audited by Gen Agent Trust Hub on Aug 6, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill includes a local utility script, scripts/verify.sh, which is used to lint milestone files for structural integrity. The script uses standard Unix tools such as grep, awk, and sed. It operates locally on user-provided files and does not perform any network operations or access sensitive system directories.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes user-defined milestone tables. It incorporates a structural validation layer via a shell script to ensure the data adheres to a specific schema (e.g., ISO dates, valid status tokens), which serves as a defensive measure against malformed or deceptive data entries.
  • [SAFE]: Analysis of the instructions, scripts, and evaluation cases revealed no evidence of prompt injection, data exfiltration, or persistence mechanisms. The skill's behavior is consistent with its stated purpose of milestone and status tracking.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 6, 2026, 09:37 PM
Security Audit — agent-trust-hub — project-ops