project-ops
Pass
Audited by Gen Agent Trust Hub on Aug 6, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill includes a local utility script,
scripts/verify.sh, which is used to lint milestone files for structural integrity. The script uses standard Unix tools such asgrep,awk, andsed. It operates locally on user-provided files and does not perform any network operations or access sensitive system directories. - [INDIRECT_PROMPT_INJECTION]: The skill processes user-defined milestone tables. It incorporates a structural validation layer via a shell script to ensure the data adheres to a specific schema (e.g., ISO dates, valid status tokens), which serves as a defensive measure against malformed or deceptive data entries.
- [SAFE]: Analysis of the instructions, scripts, and evaluation cases revealed no evidence of prompt injection, data exfiltration, or persistence mechanisms. The skill's behavior is consistent with its stated purpose of milestone and status tracking.
Audit Metadata