Security risk report for @forgecat/contains-studio_agents_project-management v0.1.2
Source Integrity
Low
Profile references a legitimate public GitHub repository (contains-studio/agents) with clear attribution and commit hash.
No typosquatted, obfuscated, or attacker-controlled package dependencies declared; no MCP servers or external binary execution defined.
Agent Intent
Low
Content describes legitimate project management workflows (experiment tracking, launch coordination, team orchestration) with no instructions to manipulate the AI, read credentials, exfiltrate data, or reveal system prompts.
Markdown provides detailed guidance on best practices (statistical rigor, launch checklists, workflow optimization) that are standard industry practices, not malicious knowledge poisoning.
No role hijacking, prompt injection phrasing, or instructions to hide/deny the agent's own instructions; no guidance to weaken security defaults or install backdoored code templates.
Details
Evidence
experiment-tracker.md: 'Your goal is to bring scientific rigor to the creative chaos of rapid app development' — describes legitimate A/B testing and data-driven decision-making.
project-shipper.md: 'Launch Readiness Checklist' and 'Risk Mitigation' sections document standard release engineering practices.
studio-producer.md: 'Studio Culture Principles: Ship Fast, Learn Faster, Trust Teams, Share Everything' — promotes transparency and team coordination, not deception or exfiltration.
Permissions
Low
Declared tools (Read, Write, MultiEdit, Grep, Glob, TodoWrite, WebSearch) are minimal and aligned with stated functions: reading/writing project files, searching documentation, and web research for market timing.
No shell execution, file deletion, or unrestricted filesystem access; no alwaysApply=true rules with broad globs; no subagent or arbitrary code execution authority.
WebSearch in project-shipper is scoped to legitimate use case (competitor analysis, market timing) and does not grant network exfiltration or credential access.
Details
Evidence
project-shipper.md: 'Analyzing competitor launch schedules' and 'Leveraging seasonal and cultural moments' justify WebSearch for market research.
All three agents use only Read/Write/Grep/Glob for local project file manipulation, consistent with their stated roles in coordination and documentation.
MCP Risk
Low
No MCP servers defined in the profile; no external binary execution, hidden tool descriptions, or unrestricted network/filesystem access.
Profile is a pure markdown agent definition with no server configuration or dynamic payload loading.