charter

Pass

Audited by Gen Agent Trust Hub on Jul 2, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: The skill processes data from external sources like Linear tickets and project briefs. While this creates a potential surface for indirect prompt injection, the skill mitigates this by generating natural-language documentation only and requiring a human reviewer to approve the content before any follow-up actions occur.
  • Ingestion points: Linear tickets, user requests, conversation history, and project playbooks.
  • Boundary markers: None detected.
  • Capability inventory: File creation and modification within the charters/ directory.
  • Sanitization: None specified.
  • [COMMAND_EXECUTION]: The skill writes files to the local filesystem. This is a legitimate functional requirement for documentation management and is restricted to the charters/ directory.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 2, 2026, 11:05 PM
Security Audit — agent-trust-hub — charter