skills/simota/agent-skills/pdm/Gen Agent Trust Hub

pdm

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from external sources to reconcile project status, creating a vulnerability surface for indirect prompt injection. 1. Ingestion points: The skill reads data from docs/*.md, gh issue list, ROADMAP.md, CHANGELOG.md, and README.md as specified in reference/source-triangulation.md. 2. Boundary markers: The instructions lack explicit boundary markers or instructions to disregard embedded commands in the ingested artifacts. 3. Capability inventory: The agent has the ability to search code files, read documentation, and interact with the gh CLI for metadata retrieval. 4. Sanitization: No sanitization or validation protocols are described for the external content before it is incorporated into the agent's context or reasoning process.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 01:49 PM
Security Audit — agent-trust-hub — pdm