sred-work-summary

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes shell commands (date, find, sed, sort) to determine the current year and identify local Git repositories for processing.
  • [INDIRECT_PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it retrieves and processes untrusted data from external platforms.
  • Ingestion points: The agent fetches titles and descriptions from GitHub Pull Requests, full text from Notion documents, and details from Linear tickets in Step 4, Step 6, and Step 7.
  • Boundary markers: The instructions do not define clear boundaries or provide guidance to the agent to ignore instructions embedded within the retrieved work items.
  • Capability inventory: The agent has access to the local shell (gh CLI, find), and write access to the user's Notion workspace.
  • Sanitization: There is no evidence of sanitization or filtering of the retrieved content before it is processed by the LLM for project grouping or written to the final Notion document.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 08:28 AM
Security Audit — agent-trust-hub — sred-work-summary