generate-status-report

Pass

Audited by Gen Agent Trust Hub on Jun 23, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill incorporates an indirect prompt injection surface by reading and acting upon the contents of local project files.\n
  • Ingestion points: The skill reads from BACKLOG.md, SPRINT-PLAN.md, WBS.md, and PROJECT-CHARTER.md (SKILL.md).\n
  • Boundary markers: The procedure lacks delimiters or specific instructions to the agent to disregard instructions that might be contained within the project artifacts.\n
  • Capability inventory: The skill allows the use of Bash, Write, and Edit tools, which could be misused if the agent inadvertently follows instructions in a processed file.\n
  • Sanitization: No input validation or sanitization is performed on the data read from the project artifacts before it is used in the report generation process.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 23, 2026, 06:43 PM
Security Audit — agent-trust-hub — generate-status-report