milestone-review
Pass
Audited by Gen Agent Trust Hub on Mar 28, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface by ingesting untrusted data from various sources and processing it without adequate security boundaries.
- Ingestion points: Reads project documentation from
production/milestones/,production/sprints/, andproduction/risk-register/, and performs aGrepscan forTODO,FIXME, andHACKmarkers across the entire codebase. - Boundary markers: The skill lacks explicit boundary markers or instructions to the agent to disregard potential instructions embedded within the ingested text.
- Capability inventory: The skill has access to the
Writetool, creating a potential risk if malicious instructions found in code comments or reports were to be executed by the agent. - Sanitization: No validation or escaping is performed on the ingested content before it is interpolated into the generated markdown report.
- [SAFE]: The skill's core logic is consistent with its stated purpose of milestone review and project status reporting.
- [SAFE]: No direct prompt injection, obfuscation, or hardcoded credentials were found in the skill's instructions or metadata.
Audit Metadata