chief-of-staff
Pass
Audited by Gen Agent Trust Hub on Jul 9, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: No malicious patterns or security violations were detected. The skill's behavior is consistent with its intended use as a task management and briefing tool.\n- [PROMPT_INJECTION]: The skill possesses an indirect prompt injection surface as it is designed to process content from potentially untrusted external sources.\n
- Ingestion points: Reads data from
workspace/tasks/current.md,workspace/relationships/current.md, and summaries of unread messages from an email inbox.\n - Boundary markers: The instructions do not specify delimiters or constraints to prevent the agent from following instructions embedded within the processed task or email content.\n
- Capability inventory: The skill has the ability to update local task files and delegate actions to other functional skills (
executive-assistant,daily-task-manager).\n - Sanitization: There is no evidence of input validation or sanitization for the data processed during briefings or reviews.
Audit Metadata