project-management-specialist

Pass

Audited by Gen Agent Trust Hub on Mar 16, 2026

Risk Level: SAFE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The 'Meeting Insights Analyzer' skill processes external transcript files (.vtt, .srt, .docx, .txt) which represent an untrusted data ingestion surface. Maliciously crafted transcripts could attempt to influence the agent's analysis or trigger other available tools.
  • Ingestion points: references/domains/meeting-intelligence/SKILL.md (scans user-provided folders for transcript files).
  • Boundary markers: Absent; the skill does not explicitly define delimiters for untrusted transcript content.
  • Capability inventory: The broader project management suite includes Bash, Write, MultiEdit, and Task capabilities across several files (issue-lifecycle/SKILL.md, experiment-tracker.md, project-shipper.md).
  • Sanitization: No specific sanitization or filtering logic is described for the content of the transcripts.
  • [COMMAND_EXECUTION]: The 'Issue Management' skill utilizes a local command-line tool ccw to perform CRUD operations on issue records stored in JSONL format. This is a standard implementation for CLI-integrated skills.
  • [EXTERNAL_DOWNLOADS]: The documentation mentions several well-known services (Zoom, Google Meet, Otter.ai, Granola, Fireflies.ai) as potential sources for meeting transcripts, which is informative and consistent with the skill's primary purpose.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 16, 2026, 04:47 AM