pm-initiate

Pass

Audited by Gen Agent Trust Hub on Apr 14, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection through the ingestion of external project data.
  • Ingestion points: The skill reads .agents/project-context.md and various project artifacts such as briefs, plans, and notes (referenced in SKILL.md).
  • Boundary markers: There are no explicit instructions or delimiters used to separate the content of these external files from the system instructions.
  • Capability inventory: The skill acts as an entry point for other PM subskills and performs data summarization, delegating tasks to specific modules based on project context (SKILL.md).
  • Sanitization: The instructions do not define any validation or sanitization steps for the data retrieved from external project documents.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 14, 2026, 07:03 PM
Security Audit — agent-trust-hub — pm-initiate