project-knowledge
Pass
Audited by Gen Agent Trust Hub on Aug 14, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill consists of instructional prompts and markdown templates intended for organizing project documentation. A thorough analysis of all skill files, including instructions and evaluation prompts, revealed no evidence of obfuscation, remote code execution, or persistence mechanisms.
- [DATA_EXFILTRATION]: The skill is configured to read and update specific documentation files, such as
GLOSSARY.mdand files withindocs/decisions/anddocs/follow-ups/. It does not attempt to access sensitive system directories (like.ssh,.aws, or.gnupg) or harvest environment variables, and it contains no instructions for external data transmission. - [PROMPT_INJECTION]: The skill instructions include safeguards to 'protect project truth', requiring explicit user confirmation before treating code behavior as a settled decision. While the skill processes project files which could technically be manipulated by external contributors (indirect prompt injection surface), the risk is minimal because the skill lacks high-risk capabilities such as network access or arbitrary command execution.
- Ingestion points: Reads from
GLOSSARY.md,docs/decisions/README.md, and various markdown files in thedocs/subdirectory. - Boundary markers: None explicitly defined in the prompts to separate project data from system instructions.
- Capability inventory: Limited to file reading and writing using standard agent tools; no network or shell access tools are utilized.
- Sanitization: No specific sanitization logic is implemented for the ingested markdown content.
Audit Metadata