pm-task-generator

Pass

Audited by Gen Agent Trust Hub on Jul 24, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill's primary function is to transform implementation details into structured markdown files for project management. It reads local requirements files and writes to a designated tasks folder.
  • [PROMPT_INJECTION]: The skill has an attack surface for indirect prompt injection as it processes external data. • Ingestion points: Reads from 'requirements.md' and receives task descriptions from the orchestrator. • Boundary markers: No explicit boundary markers or instructions to ignore embedded instructions are defined for the input data. • Capability inventory: The skill possesses file-writing capabilities restricted to the documentation task directory. • Sanitization: There is no evidence of input validation or content sanitization.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 24, 2026, 08:18 PM
Security Audit — agent-trust-hub — pm-task-generator