skills/konglong87/superpm/pm-priority/Gen Agent Trust Hub

pm-priority

Pass

Audited by Gen Agent Trust Hub on Aug 3, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes a local initialization script, check-update.sh, during its preamble. This is used for version verification and directory preparation, which is a standard operational task for this type of utility.
  • [PROMPT_INJECTION]: The skill processes requirement documents to inform its prioritization logic, representing a standard indirect prompt injection surface. • Ingestion points: The files 确认需求清单.md and 需求调研报告.md located in docs/01-需求调研/. • Boundary markers: The skill does not explicitly use delimiters or specific 'ignore' instructions when interpolating document content into subagent prompts. • Capability inventory: The skill utilizes the Read, Write, Bash, and Agent tools. • Sanitization: There is no evidence of specific sanitization or filtering logic applied to the content read from the documents before it is processed by the AI.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 3, 2026, 06:20 AM
Security Audit — agent-trust-hub — pm-priority