ln-200-scope-decomposer
Pass
Audited by Gen Agent Trust Hub on Mar 13, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill acts as a pure coordinator, delegating work to trusted local sub-skills using relative paths (e.g., ../ln-210-epic-coordinator/SKILL.md). All external references and tools originate from the same vendor/author namespace.- [PROMPT_INJECTION]: The skill has a potential surface for indirect prompt injection as it processes project documentation like requirements.md and architecture.md through its sub-skills. * Ingestion points: Documentation files (requirements.md, architecture.md, tech_stack.md) read during decomposition phases. * Boundary markers: No explicit boundary markers or delimiters for untrusted content are defined in the orchestrator logic. * Capability inventory: Sub-skills can create documents and Linear issues. * Sanitization: No explicit content sanitization or validation is specified at this orchestration level. This risk is inherent to the skill's primary purpose and is managed via downstream coordinator logic.
Audit Metadata