pm-monitor-risk-escalation
Pass
Audited by Gen Agent Trust Hub on Apr 14, 2026
Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
- [PROMPT_INJECTION]: Indirect Prompt Injection Surface\n
- Ingestion points: The skill reads project context from ".agents/project-context.md" and external project sources like status updates, RAID logs, dependency records, tracker states, and decision logs (SKILL.md, Steps 1 and 2).\n
- Boundary markers: No explicit boundary markers or "ignore embedded instructions" delimiters are specified for the input data sources.\n
- Capability inventory: The skill has no dangerous capabilities; it lacks tool definitions for network operations, file system modification, or subprocess execution across all files and evaluations.\n
- Sanitization: No input sanitization, filtering, or validation is performed on the ingested data before it is processed into the risk escalation report.\n- [NO_CODE]: The skill package does not contain any executable scripts, binaries, or code components. It consists solely of instruction sets and evaluation data.
Audit Metadata