skills/mcouthon/agents/phase-review/Gen Agent Trust Hub

phase-review

Pass

Audited by Gen Agent Trust Hub on Jun 19, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: No malicious patterns such as direct prompt injection, credential theft, or exfiltration attempts were detected.
  • [SAFE]: The skill does not perform any network operations or download external scripts.
  • [PROMPT_INJECTION]: The skill has a surface for indirect prompt injection as it processes project files (e.g., from the .tasks/ directory) which may contain untrusted data. Ingestion points: Project documentation and task files accessed via Read, Glob, and Grep. Boundary markers: None identified; instructions do not specify delimiters to isolate plan data from agent instructions. Capability inventory: The skill uses Read, Grep, Glob, Edit, and LSP tools, including file modification capabilities. Sanitization: No validation or sanitization is performed on the ingested content.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 19, 2026, 10:49 AM
Security Audit — agent-trust-hub — phase-review