utility-pm-skill-iterate
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes content from validation reports and existing files to generate proposed edits. The ingestion of potentially untrusted data is mitigated by a mandatory normalization step and the requirement for explicit user confirmation of all changes before any file operations occur.
- [COMMAND_EXECUTION]: The instructions recommend that the user manually verify changes by running a local script (bash scripts/lint-skills-frontmatter.sh). This is a standard development practice recommendation and does not involve automated or hidden command execution by the agent.
Audit Metadata