skills/lunchpaillola/project-management-skills/pm-execute-work-package-coordination/Gen Agent Trust Hub
pm-execute-work-package-coordination
Pass
Audited by Gen Agent Trust Hub on Apr 14, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: No security concerns identified. The skill performs standard project management tasks by processing text-based status updates and tracker data into a structured coordination format.
- [DATA_EXPOSURE_AND_EXFILTRATION]: Access to '.agents/project-context.md' is within the expected scope of a project management tool and does not involve exfiltration or unauthorized access.
- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from external sources like Slack messages and status notes. The attack surface is evaluated as safe because the skill's capabilities are strictly limited to text formatting and Markdown generation. Ingestion points: User prompts and external status signals (SKILL.md). Boundary markers: Absent. Capability inventory: Text formatting and Markdown generation. Sanitization: Absent.
Audit Metadata