sherpa
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [SAFE]: No security risks were identified in the skill instructions or reference documentation. The skill is constrained to task planning and does not possess capabilities for code execution or network exfiltration.
- [INDIRECT_PROMPT_INJECTION]: The skill processes user-supplied task information to generate plans, which is a potential surface for indirect injection.
- Ingestion points: User goals and task descriptions (SKILL.md).
- Boundary markers: Instructions to validate all input as raw and unverified using the INVEST checklist.
- Capability inventory: Planning and routing only; code implementation is strictly prohibited.
- Sanitization: Mitigated by strict adherence to atomic step size constraints (5-15 minutes).
- [EXTERNAL_DOWNLOADS]: Industry data and planning methodologies are referenced via links to dora.dev, linear.app, and claude.com.
- Evidence: These are trusted informational sources used for context and do not involve automated downloads or remote code execution.
Audit Metadata