resource-planner-scott-margetts

Pass

Audited by Gen Agent Trust Hub on Jun 26, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: Comprehensive analysis of the skill instructions and documentation shows no signs of malicious intent or security vulnerabilities. The skill adheres to professional boundaries, specifically acknowledging partner authority and legal project management constraints.
  • [DATA_EXPOSURE]: The skill manages sensitive business information, including matter identifiers and financial rates. However, it operates strictly within the context of legal project management and lacks any mechanisms for exfiltrating this data to external or untrusted domains. It also includes instructions to label indicative rates clearly and avoid firm-specific attribution.
  • [PROMPT_INJECTION]: No evidence of prompt injection or safety bypass attempts was found. The instructions are task-oriented and emphasize maintaining professional boundaries between legal project management and attorney-specific responsibilities.
  • [SAFE]: Indirect Prompt Injection Surface Evaluation:
  • Ingestion points: The skill is designed to ingest data from external sources such as email threads ("who has capacity?" emails), calendar entries, and WIP descriptions as described in the SKILL.md Connected Mode section.
  • Boundary markers: Explicit boundary markers for untrusted content are absent; however, the skill provides specific diagnostic warnings for self-reported capacity data to ensure the agent treats it as directional rather than definitive.
  • Capability inventory: The skill's capabilities are limited to generating structured analysis in .docx and .csv formats. It lacks high-risk capabilities such as arbitrary command execution, network exfiltration, or runtime code evaluation.
  • Sanitization: No programmatic sanitization is defined, but the skill's logic is constrained to analytical modeling which inherently limits the impact of potentially malicious embedded instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 26, 2026, 08:34 PM
Security Audit — agent-trust-hub — resource-planner-scott-margetts