skills/karlorz/llm-wiki/proj-work/Gen Agent Trust Hub

proj-work

Pass

Audited by Gen Agent Trust Hub on Jul 27, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill executes local commands through the skillwiki utility, including path for vault resolution and validate for frontmatter verification. These operations are restricted to managing local vault metadata.
  • [DATA_EXFILTRATION]: The skill reads project-specific documents and checks system-level configurations such as crontab to audit and verify completion of tasks. These read operations are limited to the local environment and intended for task validation.
  • [PROMPT_INJECTION]: The skill processes user-generated or previously written project files, presenting a potential surface for indirect prompt injection.
  • Ingestion points: Reads spec.md, tasks.md, and log.md from within projects/{slug}/work/ directories.
  • Boundary markers: None identified; the instructions do not specify the use of delimiters when reading file content.
  • Capability inventory: Filesystem read/write access, skillwiki command execution, and inspection of system configuration files.
  • Sanitization: File content is ingested for state verification without explicit sanitization or filtering logic.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 27, 2026, 11:30 AM
Security Audit — agent-trust-hub — proj-work