pm-initiate
Pass
Audited by Gen Agent Trust Hub on Apr 14, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection through the ingestion of external project data.
- Ingestion points: The skill reads .agents/project-context.md and various project artifacts such as briefs, plans, and notes (referenced in SKILL.md).
- Boundary markers: There are no explicit instructions or delimiters used to separate the content of these external files from the system instructions.
- Capability inventory: The skill acts as an entry point for other PM subskills and performs data summarization, delegating tasks to specific modules based on project context (SKILL.md).
- Sanitization: The instructions do not define any validation or sanitization steps for the data retrieved from external project documents.
Audit Metadata