pm-backlog-drift-monitor

Pass

Audited by Gen Agent Trust Hub on Jun 24, 2026

Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
  • [PROMPT_INJECTION]: Indirect prompt injection surface identified. The skill processes untrusted backlog data and possesses capabilities to perform write operations (mutations) to that data. * Ingestion points: Reads and compares current backlog against policy baseline (SKILL.md). * Boundary markers: No explicit delimiters or boundary markers are defined to separate untrusted backlog content from the agent's instructions. * Capability inventory: The skill can perform 'correction-write operations', 'mutation_gate_v2', and 'apply corrective updates' (SKILL.md). * Sanitization: No sanitization, filtering, or validation of the ingested backlog data is described.
  • [NO_CODE]: The skill consists only of markdown instructions and configuration files; no executable scripts (e.g., Python, JavaScript) are included.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 24, 2026, 05:06 AM
Security Audit — agent-trust-hub — pm-backlog-drift-monitor