project-tracking

Pass

Audited by Gen Agent Trust Hub on Aug 14, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill relies on the gh CLI for administrative operations on GitHub Projects and Issues. All commands are standard GitHub CLI invocations and GraphQL mutations intended for project management tasks.
  • [PROMPT_INJECTION]: The skill processes external data from existing issues and user-provided descriptions during planning flows. This creates a surface for indirect prompt injection (Category 8), which is mitigated by a mandatory 'confirm-first' protocol requiring explicit user approval (e.g., 'dale', 'go', 'create') before any changes are committed to GitHub. Findings for this surface are assessed as low risk due to the presence of these boundary markers and confirmation steps.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 14, 2026, 10:12 AM
Security Audit — agent-trust-hub — project-tracking