project-knowledge

Pass

Audited by Gen Agent Trust Hub on Aug 14, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill consists of instructional prompts and markdown templates intended for organizing project documentation. A thorough analysis of all skill files, including instructions and evaluation prompts, revealed no evidence of obfuscation, remote code execution, or persistence mechanisms.
  • [DATA_EXFILTRATION]: The skill is configured to read and update specific documentation files, such as GLOSSARY.md and files within docs/decisions/ and docs/follow-ups/. It does not attempt to access sensitive system directories (like .ssh, .aws, or .gnupg) or harvest environment variables, and it contains no instructions for external data transmission.
  • [PROMPT_INJECTION]: The skill instructions include safeguards to 'protect project truth', requiring explicit user confirmation before treating code behavior as a settled decision. While the skill processes project files which could technically be manipulated by external contributors (indirect prompt injection surface), the risk is minimal because the skill lacks high-risk capabilities such as network access or arbitrary command execution.
  • Ingestion points: Reads from GLOSSARY.md, docs/decisions/README.md, and various markdown files in the docs/ subdirectory.
  • Boundary markers: None explicitly defined in the prompts to separate project data from system instructions.
  • Capability inventory: Limited to file reading and writing using standard agent tools; no network or shell access tools are utilized.
  • Sanitization: No specific sanitization logic is implemented for the ingested markdown content.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 14, 2026, 07:42 AM
Security Audit — agent-trust-hub — project-knowledge