project-intake
Pass
Audited by Gen Agent Trust Hub on Mar 16, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill instructions are focused solely on documentation and organizational tasks. No indicators of obfuscation, exfiltration, or unauthorized privilege escalation were found.
- [PROMPT_INJECTION]: The skill has a surface for indirect prompt injection because it is designed to ingest and summarize untrusted data like repository links and PRD drafts. The risk level is safe because the skill's capabilities are restricted to writing non-executable markdown documentation. Ingestion points: user-provided text, PRD drafts, and repository links mentioned in SKILL.md. Boundary markers: no explicit data sanitization delimiters are used. Capability inventory: local file creation and writing to docs/00-intake.md. Sanitization: no evidence of input filtering or escaping.
Audit Metadata