chief-of-staff

Pass

Audited by Gen Agent Trust Hub on Jul 9, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: No malicious patterns or security violations were detected. The skill's behavior is consistent with its intended use as a task management and briefing tool.\n- [PROMPT_INJECTION]: The skill possesses an indirect prompt injection surface as it is designed to process content from potentially untrusted external sources.\n
  • Ingestion points: Reads data from workspace/tasks/current.md, workspace/relationships/current.md, and summaries of unread messages from an email inbox.\n
  • Boundary markers: The instructions do not specify delimiters or constraints to prevent the agent from following instructions embedded within the processed task or email content.\n
  • Capability inventory: The skill has the ability to update local task files and delegate actions to other functional skills (executive-assistant, daily-task-manager).\n
  • Sanitization: There is no evidence of input validation or sanitization for the data processed during briefings or reviews.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 9, 2026, 08:04 AM
Security Audit — agent-trust-hub — chief-of-staff