milestone-review

Pass

Audited by Gen Agent Trust Hub on Mar 28, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface by ingesting untrusted data from various sources and processing it without adequate security boundaries.
  • Ingestion points: Reads project documentation from production/milestones/, production/sprints/, and production/risk-register/, and performs a Grep scan for TODO, FIXME, and HACK markers across the entire codebase.
  • Boundary markers: The skill lacks explicit boundary markers or instructions to the agent to disregard potential instructions embedded within the ingested text.
  • Capability inventory: The skill has access to the Write tool, creating a potential risk if malicious instructions found in code comments or reports were to be executed by the agent.
  • Sanitization: No validation or escaping is performed on the ingested content before it is interpolated into the generated markdown report.
  • [SAFE]: The skill's core logic is consistent with its stated purpose of milestone review and project status reporting.
  • [SAFE]: No direct prompt injection, obfuscation, or hardcoded credentials were found in the skill's instructions or metadata.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 28, 2026, 12:12 PM
Security Audit — agent-trust-hub — milestone-review