project-cognition

Pass

Audited by Gen Agent Trust Hub on Jul 17, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill consists entirely of markdown instructions and documentation, containing no executable code, hidden scripts, or malicious automation patterns.
  • [SAFE]: Data persistence is limited to a project-specific directory (docs/cognition/), which is appropriate for its stated purpose of project modeling.
  • [SAFE]: The instructions mandate external verification of all generated claims, effectively mitigating risks of model-driven hallucinations or acceptance of unverified project data.
  • [SAFE]: An analysis of indirect prompt injection surfaces shows that while the skill ingests project source code (as seen in SKILL.md and commands/bootstrap.md), it includes explicit instructions for agents to label inferences and conflicting sources (SKILL.md Step 5), uses file-system capabilities solely for documentation artifacts, and relies on accountable external actors for final admission of claims (references/projection.md).
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 17, 2026, 06:32 AM
Security Audit — agent-trust-hub — project-cognition