specialist-project-management-project-management-jira-workflow-steward

Pass

Audited by Gen Agent Trust Hub on Aug 15, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is purely instructional, defining a specialist persona that provides templates for branch naming, commit messages, and pull requests. It does not perform any file system operations or network requests beyond text generation.
  • [DATA_EXFILTRATION]: No exfiltration risks were identified. The instructions specifically include a section on 'Security and Operational Discipline' that mandates blocking secrets, credentials, and tokens from being included in Git metadata.
  • [EXTERNAL_DOWNLOADS]: The skill references 'gitmoji.dev' and 'github.com/carloscuesta/gitmoji' as documentation references for emoji standards. These are well-known community resources used for informational purposes only; no scripts or binaries are downloaded or executed from these locations.
  • [PROMPT_INJECTION]: The skill interpolates user input via the {the_user_question} placeholder. While it lacks explicit boundary markers, the resulting subagent is a text-based specialist with no access to dangerous tools or sensitive system data, making the risk of indirect injection negligible.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 15, 2026, 08:50 PM
Security Audit — agent-trust-hub — specialist-project-management-project-management-jira-workflow-steward