work-state-and-delivery
Pass
Audited by Gen Agent Trust Hub on Aug 8, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill consists of instructional markdown files that guide an AI agent on project management, documentation, and commit policies. No executable code, scripts, or external dependencies are included.
- [DATA_EXPOSURE]: The skill demonstrates proactive security awareness by explicitly requiring that delivery records omit secrets, private transcripts, sensitive payloads, and large temporary artifacts.
- [COMMAND_EXECUTION]: The instructions refer to standard
gitoperations (such asgit status,git diff, andgit add) which are within the expected scope for a development-focused skill and do not present an escalation risk. - [INDIRECT_PROMPT_INJECTION]: The skill describes ingesting data from external sources like issue trackers and design documents. However, the instructions focus on structural mapping, status updates, and documentation organization rather than the execution of commands found within that data, mitigating the risk of indirect prompt injection.
Audit Metadata