pma
Pass
Audited by Gen Agent Trust Hub on May 11, 2026
Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [PROMPT_INJECTION]: The skill implements a file-based task and plan tracking system in the docs/ directory that guides agent behavior, creating an indirect prompt injection surface. Ingestion points: The agent reads docs/task/ and docs/plan/ files at session start and during workflow transitions. Boundary markers: No specific delimiters or instructions are provided to separate task content from agent commands. Capability inventory: The agent has the ability to execute bash/tmux commands, perform git operations, and modify the filesystem. Sanitization: Repository-hosted documentation is processed directly without validation.
- [COMMAND_EXECUTION]: The skill defines specific shell patterns and conventions for managing persistent development processes and server execution using bash and tmux.
- [EXTERNAL_DOWNLOADS]: The skill recommends and integrates the use of the @nsio/nsl Node.js package for local reverse proxying and development-time network routing.
Audit Metadata