fid-lifecycle

Pass

Audited by Gen Agent Trust Hub on Sep 13, 2026

Risk Level: SAFENO_CODE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to process content from potentially untrusted sources such as project backlogs, founder's notes, and Jira ticket descriptions.
  • Ingestion points: The skill ingests data from the Backlog, founder's notes, FID pages, and Jira tickets (SKILL.md).
  • Boundary markers: There are no explicit instructions to use delimiters or ignore instructions embedded within the processed content.
  • Capability inventory: The skill involves reading, writing, and updating records in Jira and Confluence platforms.
  • Sanitization: There is no mention of sanitizing or validating the input data before it is moved or link to other systems.
  • [NO_CODE]: The skill provides procedural instructions for human or agent hygiene in project management and does not contain any executable scripts, shell commands, or external dependencies.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 13, 2026, 02:20 AM
Security Audit — agent-trust-hub — fid-lifecycle