pm-initiate-budget

Pass

Audited by Gen Agent Trust Hub on Apr 15, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is designed to manage a local project budget file (defaulting to .agents/project-budget.md). It reads and writes structured data in a Markdown table format and does not access sensitive directories like SSH or AWS configurations.- [SAFE]: No network operations (such as curl or wget) or external data exfiltration patterns were detected. All operations are local to the project environment.- [SAFE]: The skill does not include any obfuscation, hardcoded credentials, or persistence mechanisms. No third-party dependencies or remote scripts are downloaded or executed.- [SAFE]: While the skill reads external data from a file which represents a potential surface for indirect prompt injection (Category 8), the capabilities are restricted to simple file management without execution or network access. 1. Ingestion points: .agents/project-budget.md. 2. Boundary markers: Absent. 3. Capability inventory: Local file read/write operations. 4. Sanitization: Absent.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 15, 2026, 12:06 PM
Security Audit — agent-trust-hub — pm-initiate-budget