pm-close

Pass

Audited by Gen Agent Trust Hub on Apr 14, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [SAFE]: No malicious patterns, obfuscation, or persistence mechanisms were detected. The skill instructions are consistent with the stated project management purpose and lack dangerous capabilities.\n- [PROMPT_INJECTION]: The skill exhibits a surface for indirect prompt injection because it incorporates external data into its workflow.\n
  • Ingestion points: The workflow reads .agents/project-context.md during the objective confirmation step to gather context.\n
  • Boundary markers: The skill does not provide the agent with specific delimiters or instructions to ignore potential commands embedded within the ingested project context file.\n
  • Capability inventory: The skill has no access to high-risk tools or commands, such as network requests, file writing, or subprocess execution; its functionality is limited to generating text-based summaries.\n
  • Sanitization: No validation or sanitization is performed on the data read from the project context file.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 14, 2026, 07:03 PM
Security Audit — agent-trust-hub — pm-close