project-long-task

Pass

Audited by Gen Agent Trust Hub on Mar 7, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: Comprehensive analysis of the skill's instructions and structure confirms the absence of malicious code, hidden commands, or unauthorized data access patterns.- [PROMPT_INJECTION]: The skill generates an execution protocol for agents that requires specific behavioral markers, such as responding with 'Hey Jacky Bro' to verify context loading and proceeding through milestones without human confirmation. These directives are within the scope of the skill's functional purpose as a long-running task manager.- [PROMPT_INJECTION]: The skill presents an indirect prompt injection surface as it generates implementation plans based on unvalidated user input. Ingestion points: User input from 'Step 2 — Project Goals' and 'Step 3 — Clarifying Questions' in SKILL.md. Boundary markers: No delimiters or instructions to ignore embedded commands are included in the generated docs/plans.md or docs/architecture.md. Capability inventory: The generated docs/implement.md grants the agent permission to perform file writes and execute terminal commands (lint, build, test) autonomously. Sanitization: The skill does not perform sanitization or schema validation on the user's project description before incorporating it into the execution plan.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 7, 2026, 06:13 AM