project-management
Pass
Audited by Gen Agent Trust Hub on Aug 18, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructions direct the agent to use a shell command
vault.shfor project initialization. This command incorporates user-defined parameters such as project name, owner, and company, which could lead to command injection if input is not properly handled by the underlying tool. - [PROMPT_INJECTION]: The skill is designed to ingest and act upon data stored within an Obsidian vault, including project goals, milestones, and status updates. This creates an attack surface for indirect prompt injection where malicious instructions embedded in vault notes could influence agent behavior. 1. Ingestion points: Project notes, task acceptance criteria, risk logs, and decision notes retrieved from the user's Obsidian vault (specified in SKILL.md and references/pm-system.md). 2. Boundary markers: The instructions do not define clear delimiters or specific instructions for the agent to ignore potentially malicious content within the project data. 3. Capability inventory: The skill has the ability to execute shell commands (
vault.sh) and perform file operations through the referencedsecond-brainskill. 4. Sanitization: There are no explicit instructions or logic provided to sanitize or validate the project data before it is processed or used in shell command templates.
Audit Metadata