persona-project-manager
Pass
Audited by Gen Agent Trust Hub on Jul 15, 2026
Risk Level: SAFE
Full Analysis
- [PROMPT_INJECTION]: The skill contains no instructions designed to bypass agent constraints, extract system prompts, or override safety protocols.
- [DATA_EXFILTRATION]: No unauthorized data access or exfiltration patterns were found. The skill operates within the scope of Google Workspace tools to manage project artifacts, which is consistent with its stated purpose.
- [COMMAND_EXECUTION]: The skill utilizes the 'gws' (Google Workspace) CLI tool and 'jq' for data processing. These are standard utility tools for the intended functionality and no dangerous shell injections or privilege escalation attempts were detected.
- [REMOTE_CODE_EXECUTION]: There are no patterns involving the download or execution of remote scripts or unverified third-party code.
- [INDIRECT_PROMPT_INJECTION]: While the skill processes untrusted external data (such as emails via
gws-gmailand documents viagws-drive), this is inherent to the functionality of a project manager persona. The risk is considered low as the skill follows standard workflows and encourages the use of '--dry-run' for write operations.
Audit Metadata