collab-roadmap

Pass

Audited by Gen Agent Trust Hub on Aug 19, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill manages project lifecycle data by creating a local _workspace/ directory and generating various markdown files, such as 01_project_plan.md and 04_risk_plan.md, to document planning and risk management outcomes.
  • [EXTERNAL_DOWNLOADS]: The strategy involves delegating specialized tasks to other skills within the MoAI ecosystem, including moai-lawyer:legal-contract-review for legal oversight and moai-writer:korean-humanize for final content polishing.
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it processes untrusted user-provided project details and incorporates them into generated planning documents. (1) Ingestion points: User project descriptions, resource constraints, and identified risks are extracted and stored in _workspace/00_input.md as described in references/project-tracker.md. (2) Boundary markers: No explicit delimiters or instructions are provided to the agent to treat user-provided project data as potentially untrusted content. (3) Capability inventory: The skill utilizes file system access to create, write, and organize files within the specified workspace directory. (4) Sanitization: There are no defined processes for sanitizing or validating the project data before it is used to generate downstream planning documents.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 19, 2026, 01:41 PM
Security Audit — agent-trust-hub — collab-roadmap