skills/simota/agent-skills/pdm/Gen Agent Trust Hub

pdm

Pass

Audited by Gen Agent Trust Hub on Jun 17, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [SAFE]: No security threats were identified. The skill is designed as a read-only navigator with strong principles of evidence-based reporting and intent-vs-reality separation.\n- [COMMAND_EXECUTION]: The skill provides instructions to use the gh CLI for retrieving project data such as issues, labels, and milestones. These are standard, read-only interactions with the project repository metadata.\n- [EXTERNAL_DOWNLOADS]: Project-related metadata is retrieved from GitHub. These operations target a well-known service and are limited to fetching descriptive project artifacts rather than executable code.\n- [PROMPT_INJECTION]: The skill evaluates external content like issue descriptions and specifications. While this constitutes a surface for indirect prompt injection, the risk is mitigated by the skill's read-only nature and its requirement for grounding all claims in code evidence (file:line).
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 17, 2026, 12:20 AM
Security Audit — agent-trust-hub — pdm