project-knowledge

Pass

Audited by Gen Agent Trust Hub on Aug 26, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses subprocess.run to interact with the local git binary and a sibling skill script (project-state/run.sh). These operations are constrained to retrieving project metadata (e.g., commit logs, top-level directory names) and generating status reports, which is consistent with its stated purpose of knowledge management.
  • [PROMPT_INJECTION]: The skill represents a surface for indirect prompt injection as it processes and updates PROJECT_KNOWLEDGE.md, a document intended for shared human/agent collaboration. Adversarial instructions placed in this file could potentially influence agent behavior during subsequent retrieval or reading operations.
  • Ingestion points: PROJECT_KNOWLEDGE.md (read via local file access), git log output, and output from the project-state skill.
  • Boundary markers: The skill does not explicitly wrap ingested external content in restrictive boundary markers or "ignore embedded instructions" warnings during interpolation.
  • Capability inventory: The skill possesses file-writing capabilities and can execute local shell commands via subprocess.run.
  • Sanitization: Content is parsed into markdown sections and metadata is slugified for tags, but the core text is processed without extensive sanitization against natural language instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 26, 2026, 06:01 PM
Security Audit — agent-trust-hub — project-knowledge