project-knowledge

Pass

Audited by Gen Agent Trust Hub on Aug 5, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill's primary function is to manage local project documentation (GLOSSARY.md and docs/decisions/). It contains no instructions for network access, external downloads, or execution of arbitrary code.
  • [PROMPT_INJECTION]: The skill includes instructions to 'Challenge unclear terms' and 'Resolve vague, overloaded, or conflicting language with the user.' These are benign instructional guidelines intended to improve documentation quality and do not attempt to bypass AI safety filters or override core agent behavior.
  • [COMMAND_EXECUTION]: There is no evidence of shell command execution. The skill focuses on reading and writing markdown files using standard file system tools.
  • [DATA_EXFILTRATION]: No network operations or external URLs were found. All activities are confined to the local repository.
  • [CREDENTIALS_UNSAFE]: No hardcoded secrets, API keys, or instructions to access sensitive files like .env or ~/.ssh were detected.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 5, 2026, 06:04 AM
Security Audit — agent-trust-hub — project-knowledge