premortem
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill implements a defensive risk-analysis framework based on established industry practices (Shreyas Doshi/Gary Klein). It explicitly instructs the agent to verify findings through context reading, fallback checking, and scope validation, which serves as a robust safety mechanism against hallucinations or incorrect technical assessments.
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process untrusted data such as project plans, pull requests, and source code. While this presents a surface for indirect prompt injection, the skill includes built-in mitigations including mandatory verification steps and a required human-in-the-loop checkpoint via the
AskUserQuestiontool before any findings are accepted or acted upon. - [EXTERNAL_DOWNLOADS]: The skill provides references to well-known and reputable educational resources (Harvard Business Review, Coda, Mountain Goat Software) for the purposes of methodology documentation. These links are static, informational, and do not lead to executable content downloads.
Audit Metadata