project-execution

Pass

Audited by Gen Agent Trust Hub on Aug 10, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to execute directory listing commands (ls) on first activation to check for installed companion skills in standard paths such as ~/.claude/skills/ and ~/.agent/skills/. This is a utility feature intended to provide recommendations for missing dependencies.
  • [EXTERNAL_DOWNLOADS]: The skill encourages the acquisition of additional modules from the AbsolutelySkilled repository using the npx skills add command. This is part of the skill's intended ecosystem for extended functionality.
  • [PROMPT_INJECTION]: The skill acts as a surface for indirect prompt injection (Category 8) as it processes external project data like risk descriptions and stakeholder roles.
  • Ingestion points: Reads project plans, risk registers, and stakeholder matrices provided by the user.
  • Boundary markers: The instructions do not define specific delimiters for separating user data from system instructions.
  • Capability inventory: The skill has the capability to run shell commands (ls) and suggest package installations (npx).
  • Sanitization: No explicit sanitization or validation of the processed data is mentioned.
  • Risk Assessment: Given the focused operational scope of the skill, the risk is categorized as low.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 10, 2026, 02:06 PM
Security Audit — agent-trust-hub — project-execution