daily-standup-coach
Pass
Audited by Gen Agent Trust Hub on Sep 4, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from the local environment to generate reports.
- Ingestion points: In
SKILL.md(Step 1) andagents/openai.yaml(Step 1), the agent is instructed to reviewgit logoutput and modified files from the past 24 hours. - Boundary markers: The instructions do not specify delimiters or techniques to isolate git commit messages from the system prompt.
- Capability inventory: The skill utilizes
bash,view_file,write_to_file, andreplace_file_contentas declared in theSKILL.mdfrontmatter. - Sanitization: No explicit filtering or sanitization of git logs is performed before processing by the model.
- [EXTERNAL_DOWNLOADS]: The
README.mdfile contains installation instructions usingnpx skills add harshsinghmp/muse-skills. This refers to the skill author's own repository and is a standard distribution mechanism. - [COMMAND_EXECUTION]: The skill uses
bashto executegit log --since="24 hours ago"inSKILL.md. This is a read-only operation restricted to the local repository metadata to fulfill the skill's primary purpose of summarizing daily activity.
Audit Metadata