light-memory-pm
Pass
Audited by Gen Agent Trust Hub on Jun 13, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill provides detailed instructions for the agent to orchestrate several command-line tools including Git (for versioning), DVC (for data pipelines), and the GitHub CLI (for milestone and task tracking).
- [EXTERNAL_DOWNLOADS]: The skill integrates with well-known research and productivity platforms. It fetches literature data from the Zotero Web API and synchronizes project knowledge with services like Notion and GitHub.
- [DATA_EXFILTRATION]: Research project metadata, experimental metrics, and status updates are synchronized with external experiment-tracking platforms (MLflow, Weights & Biases, W&B). These data transfers are intrinsic to the skill's primary function as a research project manager.
- [PROMPT_INJECTION]: The skill processes data from external sources such as literature titles/abstracts from Zotero and outputs from various developer tools. This represents an indirect prompt injection surface.
- Ingestion points: Research project database (db09), Zotero bibliography items, and Git logs.
- Boundary markers: None explicitly defined in the project templates to isolate processed data from core instructions.
- Capability inventory: Subprocess execution of development tools and extensive file system write access for project persistence.
- Sanitization: No explicit validation or filtering logic for ingested research data is described.
Audit Metadata