project-execution
Pass
Audited by Gen Agent Trust Hub on Aug 10, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to execute directory listing commands (
ls) on first activation to check for installed companion skills in standard paths such as~/.claude/skills/and~/.agent/skills/. This is a utility feature intended to provide recommendations for missing dependencies. - [EXTERNAL_DOWNLOADS]: The skill encourages the acquisition of additional modules from the
AbsolutelySkilledrepository using thenpx skills addcommand. This is part of the skill's intended ecosystem for extended functionality. - [PROMPT_INJECTION]: The skill acts as a surface for indirect prompt injection (Category 8) as it processes external project data like risk descriptions and stakeholder roles.
- Ingestion points: Reads project plans, risk registers, and stakeholder matrices provided by the user.
- Boundary markers: The instructions do not define specific delimiters for separating user data from system instructions.
- Capability inventory: The skill has the capability to run shell commands (
ls) and suggest package installations (npx). - Sanitization: No explicit sanitization or validation of the processed data is mentioned.
- Risk Assessment: Given the focused operational scope of the skill, the risk is categorized as low.
Audit Metadata