understand-project

Pass

Audited by Gen Agent Trust Hub on Sep 9, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process a wide variety of project files and metadata, including AGENTS.md, CLAUDE.md, source code, tests, Kanban tasks, and durable specifications. These external inputs could contain malicious instructions designed to influence the agent's behavior during the planning or implementation phases.
  • Ingestion points: Reads AGENTS.md, CLAUDE.md, repository status, source code, tests, product documentation, Kanban tasks, and durable specs as specified in steps 1 and 2 of SKILL.md.
  • Boundary markers: No explicit delimiters or instructions are provided to the agent to treat this ingested content as untrusted data or to ignore embedded instructions.
  • Capability inventory: The skill interacts with the vendor's task management utility (yy) and writes durable specifications to the filesystem.
  • Sanitization: No explicit sanitization, validation, or filtering of the external content is described before the data is processed or handed off to other tools.
  • [COMMAND_EXECUTION]: The skill instructs the agent to execute a CLI tool (yy) to start task-specific worktrees (yy task start TASK_ID). This involves command-line interaction with a utility provided by the skill author.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 9, 2026, 12:01 AM
Security Audit — agent-trust-hub — understand-project