project-knowledge
Pass
Audited by Gen Agent Trust Hub on Aug 26, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses
subprocess.runto interact with the localgitbinary and a sibling skill script (project-state/run.sh). These operations are constrained to retrieving project metadata (e.g., commit logs, top-level directory names) and generating status reports, which is consistent with its stated purpose of knowledge management. - [PROMPT_INJECTION]: The skill represents a surface for indirect prompt injection as it processes and updates
PROJECT_KNOWLEDGE.md, a document intended for shared human/agent collaboration. Adversarial instructions placed in this file could potentially influence agent behavior during subsequent retrieval or reading operations. - Ingestion points:
PROJECT_KNOWLEDGE.md(read via local file access),git logoutput, and output from theproject-stateskill. - Boundary markers: The skill does not explicitly wrap ingested external content in restrictive boundary markers or "ignore embedded instructions" warnings during interpolation.
- Capability inventory: The skill possesses file-writing capabilities and can execute local shell commands via
subprocess.run. - Sanitization: Content is parsed into markdown sections and metadata is slugified for tags, but the core text is processed without extensive sanitization against natural language instructions.
Audit Metadata