sred-project-organizer

Pass

Audited by Gen Agent Trust Hub on Aug 14, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: The skill ingests untrusted data from GitHub Pull Requests, Linear tickets, and Notion documents to perform summarization. This creates an indirect prompt injection surface where instructions within that data could potentially influence the agent's output. This behavior is inherent to the skill's primary purpose of summarizing technical work.
  • Ingestion points: Notion links, GitHub PRs, and Linear tickets accessed in SKILL.md Steps 1, 2, 5.4, and 5.6.
  • Boundary markers: The skill does not define specific boundary markers or 'ignore' instructions for the external data it processes.
  • Capability inventory: Access to Notion, GitHub, and Linear APIs for data retrieval and Notion document creation. The skill does not have capabilities for arbitrary code execution, network exfiltration to unknown domains, or persistence.
  • Sanitization: No data sanitization or filtering is implemented for the ingested content.
  • [COMMAND_EXECUTION]: The skill utilizes the gh (GitHub) CLI tool to fetch repository data. This is a standard developer tool used as intended for the skill's documented purpose.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 14, 2026, 01:43 PM
Security Audit — agent-trust-hub — sred-project-organizer