pm-os-setup
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the AI agent to execute local scaffolding scripts (
scaffold-pm-os.shandscaffold-pm-os.ps1) to initialize the workspace directory structure. These scripts use standard local utilities for directory creation and file templating. Additionally, the agent is instructed to perform folder renames using shell or PowerShell commands during the personalization phase. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to process untrusted external data such as meeting notes, transcripts, and product documents.
- Ingestion points: Untrusted data enters the agent context through the processing of raw notes in
meeting-summarizer.mdand feature context inprd-writer.md. - Boundary markers: The skill explicitly instructs the agent to separate raw untrusted input into dedicated
raw/folders and to create summaries or synthesized artifacts separately, which provides a logical boundary between untrusted input and agent-generated content. - Capability inventory: The agent has the capability to write and rename files and directories, and to execute local scripts and other agent-based skills.
- Sanitization: The skill relies on the structural separation of content rather than explicit text sanitization or filtering.
- [EXTERNAL_DOWNLOADS]: The skill references a trusted external repository (
github.com/anthropics/skills) for a 'skill-creator' tool. This is documented neutrally as a recommendation for authoring new skills and Anthropics is a recognized trusted organization.
Audit Metadata