project-management

Pass

Audited by Gen Agent Trust Hub on Aug 18, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructions direct the agent to use a shell command vault.sh for project initialization. This command incorporates user-defined parameters such as project name, owner, and company, which could lead to command injection if input is not properly handled by the underlying tool.
  • [PROMPT_INJECTION]: The skill is designed to ingest and act upon data stored within an Obsidian vault, including project goals, milestones, and status updates. This creates an attack surface for indirect prompt injection where malicious instructions embedded in vault notes could influence agent behavior. 1. Ingestion points: Project notes, task acceptance criteria, risk logs, and decision notes retrieved from the user's Obsidian vault (specified in SKILL.md and references/pm-system.md). 2. Boundary markers: The instructions do not define clear delimiters or specific instructions for the agent to ignore potentially malicious content within the project data. 3. Capability inventory: The skill has the ability to execute shell commands (vault.sh) and perform file operations through the referenced second-brain skill. 4. Sanitization: There are no explicit instructions or logic provided to sanitize or validate the project data before it is processed or used in shell command templates.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 18, 2026, 07:15 PM
Security Audit — agent-trust-hub — project-management