generate-status-report
Pass
Audited by Gen Agent Trust Hub on Jun 23, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill incorporates an indirect prompt injection surface by reading and acting upon the contents of local project files.\n
- Ingestion points: The skill reads from
BACKLOG.md,SPRINT-PLAN.md,WBS.md, andPROJECT-CHARTER.md(SKILL.md).\n - Boundary markers: The procedure lacks delimiters or specific instructions to the agent to disregard instructions that might be contained within the project artifacts.\n
- Capability inventory: The skill allows the use of
Bash,Write, andEdittools, which could be misused if the agent inadvertently follows instructions in a processed file.\n - Sanitization: No input validation or sanitization is performed on the data read from the project artifacts before it is used in the report generation process.
Audit Metadata