delivery-timeline
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill operates entirely on local project artifacts (YAML files) to perform timeline calculations. It does not request network access, access sensitive system credentials, or interact with external services.
- [INDIRECT_PROMPT_INJECTION]: The skill processes data from a
milestones.yamlfile, which constitutes an indirect prompt injection surface. However, the risk is negligible as the skill lacks dangerous capabilities (such as network tools or unrestricted shell execution) that could be exploited via malicious data content.
Audit Metadata