specialist-project-management-project-manager-senior

Pass

Audited by Gen Agent Trust Hub on Aug 15, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: The skill interpolates user-provided input via the {the_user_question} variable into the instructions for a spawned sub-agent. This represents a standard indirect prompt injection surface where external input is processed by the agent, but the skill itself does not contain malicious override attempts.
  • [COMMAND_EXECUTION]: The skill employs the Agent tool to coordinate multi-agent workflows by spawning a specialized 'Senior Project Manager' agent. This is an intended orchestration capability and does not involve the execution of arbitrary shell commands or unauthorized system calls.
  • [DATA_EXPOSURE]: While the skill is designed to read 'site specification files', it lacks any mechanisms for exfiltrating this data to external servers or accessing sensitive system directories like SSH keys or environment variables.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 15, 2026, 08:49 PM
Security Audit — agent-trust-hub — specialist-project-management-project-manager-senior