skills/tjcages/skills/progress-check/Gen Agent Trust Hub

progress-check

Pass

Audited by Gen Agent Trust Hub on Aug 25, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [UNVERIFIABLE_DEPENDENCIES_AND_REMOTE_CODE_EXECUTION]: The skill provides instructions for global installation using npx skills add tjcages/skills, which involves downloading and executing code from the author's package on the NPM registry.
  • [PERSISTENCE_MECHANISMS]: The "Install globally" mode contains instructions for the agent to modify user-level configuration files and instruction blocks to ensure the progress-tracking behavior persists across different AI sessions and projects.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes project milestones and task evidence to generate updates, creating a surface where instructions embedded in task data could potentially influence the agent's progress reporting, though the skill does not grant the agent high-privilege capabilities.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 25, 2026, 09:08 PM
Security Audit — agent-trust-hub — progress-check