collab-pm-report

Pass

Audited by Gen Agent Trust Hub on Aug 19, 2026

Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to fetch and process data from external sources, which creates a potential surface for indirect prompt injection if those sources contain malicious instructions.
  • Ingestion points: Data is retrieved from Notion, Linear, and Asana via MCP tools, or via manual CSV/JSON uploads and free-text input as described in Workflow Step 1 of SKILL.md.
  • Boundary markers: The instructions do not define clear delimiters (e.g., XML tags or unique markers) or specific "ignore" instructions for the agent to separate untrusted external data from the skill's operational logic.
  • Capability inventory: The skill allows the agent to synthesize report content, apply tones, and generate executive summaries based on the ingested data, which could be manipulated if the source data contains adversarial content.
  • Sanitization: There are no explicit requirements or steps for the agent to sanitize, escape, or validate the content fetched from the external project management tools before it is interpolated into the final report output.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 19, 2026, 01:41 PM
Security Audit — agent-trust-hub — collab-pm-report