skills/mtngtools/agents/whats-next/Gen Agent Trust Hub

whats-next

Pass

Audited by Gen Agent Trust Hub on Sep 9, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill provides structured instructions for managing project tasks and generating workflow prompts. It does not contain any malicious code, obfuscation, or unauthorized access patterns.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests data from external issue trackers (GitHub) to generate task prompts, which is an expected behavior for its primary purpose.
  • Ingestion points: GitHub ticket metadata, status reports, and backlog items described in SKILL.md.
  • Boundary markers: The instructions do not define specific markers to delimit external ticket content from the generated prompts.
  • Capability inventory: The skill generates prompts intended to trigger other commands such as /implement and /prototype.
  • Sanitization: There is no mention of sanitizing or validating external content before it is processed or included in the output prompts.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 9, 2026, 10:35 PM
Security Audit — agent-trust-hub — whats-next