okr-resource

Pass

Audited by Gen Agent Trust Hub on May 9, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: No malicious patterns or security risks were detected. The skill performs localized file operations to manage project metadata and resource documentation.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes project-specific data which could theoretically contain instructions, though the impact is limited to local file modification.
  • Ingestion points: Reads .okr/plan.md and frontmatter from files in .okr/actions/*.md (SKILL.md).
  • Boundary markers: Absent. The skill does not explicitly instruct the agent to ignore instructions embedded within the files it reads.
  • Capability inventory: Limited to reading and writing local files; no network operations, command execution, or dynamic code execution capabilities are present.
  • Sanitization: No content validation or sanitization is performed on the data read from the project files.
Audit Metadata
Risk Level
SAFE
Analyzed
May 9, 2026, 10:29 AM
Security Audit — agent-trust-hub — okr-resource