light-memory-pm

Pass

Audited by Gen Agent Trust Hub on Jun 13, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides detailed instructions for the agent to orchestrate several command-line tools including Git (for versioning), DVC (for data pipelines), and the GitHub CLI (for milestone and task tracking).
  • [EXTERNAL_DOWNLOADS]: The skill integrates with well-known research and productivity platforms. It fetches literature data from the Zotero Web API and synchronizes project knowledge with services like Notion and GitHub.
  • [DATA_EXFILTRATION]: Research project metadata, experimental metrics, and status updates are synchronized with external experiment-tracking platforms (MLflow, Weights & Biases, W&B). These data transfers are intrinsic to the skill's primary function as a research project manager.
  • [PROMPT_INJECTION]: The skill processes data from external sources such as literature titles/abstracts from Zotero and outputs from various developer tools. This represents an indirect prompt injection surface.
  • Ingestion points: Research project database (db09), Zotero bibliography items, and Git logs.
  • Boundary markers: None explicitly defined in the project templates to isolate processed data from core instructions.
  • Capability inventory: Subprocess execution of development tools and extensive file system write access for project persistence.
  • Sanitization: No explicit validation or filtering logic for ingested research data is described.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 13, 2026, 05:04 AM
Security Audit — agent-trust-hub — light-memory-pm