pdm
Pass
Audited by Gen Agent Trust Hub on Jun 17, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [SAFE]: No security threats were identified. The skill is designed as a read-only navigator with strong principles of evidence-based reporting and intent-vs-reality separation.\n- [COMMAND_EXECUTION]: The skill provides instructions to use the
ghCLI for retrieving project data such as issues, labels, and milestones. These are standard, read-only interactions with the project repository metadata.\n- [EXTERNAL_DOWNLOADS]: Project-related metadata is retrieved from GitHub. These operations target a well-known service and are limited to fetching descriptive project artifacts rather than executable code.\n- [PROMPT_INJECTION]: The skill evaluates external content like issue descriptions and specifications. While this constitutes a surface for indirect prompt injection, the risk is mitigated by the skill's read-only nature and its requirement for grounding all claims in code evidence (file:line).
Audit Metadata