pm-monitor-risk-escalation

Pass

Audited by Gen Agent Trust Hub on Apr 14, 2026

Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
  • [PROMPT_INJECTION]: Indirect Prompt Injection Surface\n
  • Ingestion points: The skill reads project context from ".agents/project-context.md" and external project sources like status updates, RAID logs, dependency records, tracker states, and decision logs (SKILL.md, Steps 1 and 2).\n
  • Boundary markers: No explicit boundary markers or "ignore embedded instructions" delimiters are specified for the input data sources.\n
  • Capability inventory: The skill has no dangerous capabilities; it lacks tool definitions for network operations, file system modification, or subprocess execution across all files and evaluations.\n
  • Sanitization: No input sanitization, filtering, or validation is performed on the ingested data before it is processed into the risk escalation report.\n- [NO_CODE]: The skill package does not contain any executable scripts, binaries, or code components. It consists solely of instruction sets and evaluation data.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 14, 2026, 07:03 PM
Security Audit — agent-trust-hub — pm-monitor-risk-escalation