pm-stakeholder-communication
Pass
Audited by Gen Agent Trust Hub on Jul 19, 2026
Risk Level: SAFE
Full Analysis
- [PROMPT_INJECTION]: The skill contains no instructions designed to bypass safety filters, override system prompts, or extract internal agent instructions. The instructions are focused on guiding the user through a project management workflow.
- [DATA_EXFILTRATION]: There are no network operations, hardcoded credentials, or access requests to sensitive system files such as SSH keys or environment variables. All data handling is confined to the local document creation process.
- [REMOTE_CODE_EXECUTION]: The skill does not perform any external downloads or execute scripts from remote sources. It relies on local templates and the agent's native capabilities.
- [COMMAND_EXECUTION]: Although 'Bash' is listed in the allowed tools, it is intended for project documentation tasks (e.g., file management or document conversion). No suspicious or unauthorized command patterns were found in the instructions.
- [SAFE]: The skill uses local file references for its framework and output guidelines, which is a standard practice for modular agent skills and poses no security risk.
Audit Metadata