project-mngt
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze external requirement documents (BRD, PRD, User Stories) provided by users. This creates a surface for indirect prompt injection if those documents contain malicious instructions designed to influence the agent's behavior during the planning phase. However, the skill does not grant the agent any high-privilege capabilities (such as code execution, network exfiltration, or filesystem writes beyond the plan generation) that would allow an attacker to exploit this surface for malicious outcomes.
- [SAFE]: The skill is entirely instructional markdown and does not reference any external packages, remote scripts, or executable code. It adheres to standard planning methodologies and includes clear version control and change management protocols to preserve the integrity of completed work.
Audit Metadata