phase-review
Pass
Audited by Gen Agent Trust Hub on Jun 19, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: No malicious patterns such as direct prompt injection, credential theft, or exfiltration attempts were detected.
- [SAFE]: The skill does not perform any network operations or download external scripts.
- [PROMPT_INJECTION]: The skill has a surface for indirect prompt injection as it processes project files (e.g., from the
.tasks/directory) which may contain untrusted data. Ingestion points: Project documentation and task files accessed viaRead,Glob, andGrep. Boundary markers: None identified; instructions do not specify delimiters to isolate plan data from agent instructions. Capability inventory: The skill usesRead,Grep,Glob,Edit, andLSPtools, including file modification capabilities. Sanitization: No validation or sanitization is performed on the ingested content.
Audit Metadata