Skip to content
Report library
Purpose / Other

Persona Team Lead Skill Security Audit

What the author says it does (original text)

Lead a team — run standups, coordinate tasks, and communicate.

Independent security check

Do not install or run it yet

Files checked
1
Risks found
3
Could it run dangerous commands?Looks for programs run straight after downloading, remote control of your computer, and hidden commands.No risks found
Could it expose your files or keys?Looks for uploads of files containing passwords or keys, and keys written directly in the code.Risks found: 1
High risk

Standup reports are directed to team Chat and may expose sensitive team information

Source references: 3
What we found

The Skill explicitly says to share standup output in team Chat and suggests a message-creation command. Sanitization is only an optional tip, not a mandatory pre-send step, and the visible instructions do not require confirmation of the destination space or a content preview.

Why this matters

Personnel status, blockers, project details, or other sensitive standup information could be posted to an overly broad Chat space and remain accessible under that space's membership and retention rules.

This is an active instruction to share generated standup output in team Chat, with a message-creation command suggested for delivery. Sanitization is only a tip, not a mandatory precondition. If the report contains staff status, blockers, or other internal details, sending it to the wrong or overly broad space could disclose them. A user can require a preview, explicit destination confirmation, and mandatory `--sanitize` before sending.

SKILL.md:32In the instructionsOpen original file
## Instructions- Run daily standups with `gws workflow +standup-report` — share output in team Chat.- Prepare for 1:1s with `gws workflow +meeting-prep`.
Show 2 other places
SKILL.md:40In the instructionsOpen original file
- Use `gws calendar +agenda --week --format table` for weekly team calendar views.- Pipe standup reports to Chat with `gws chat spaces messages create`.- Use `--sanitize` for any operations involving sensitive team data.
SKILL.md:41In the instructionsOpen original file
- Pipe standup reports to Chat with `gws chat spaces messages create`.- Use `--sanitize` for any operations involving sensitive team data.
Could it delete files or keep running?Looks for broad file deletion, disk overwrites, and programs set to start automatically.Risks found: 1
Medium risk

The Skill is directed to append to a shared OKR sheet, creating persistent collaborative-document changes

Source references: 2
What we found

The Skill says to track team OKRs using `gws sheets +append`, which adds content to a shared spreadsheet. The visible instructions do not identify the destination sheet, permitted row structure, pre-write preview, or per-write confirmation.

Why this matters

Selecting the wrong spreadsheet or generating incorrect content could corrupt the team's authoritative OKR record, expose goal information, or affect reports and decisions that depend on the sheet.

This actively instructs use of `sheets +append` to track team OKRs; “append” indicates a persistent addition to a spreadsheet. The action is consistent with the skill’s team-management purpose, but no target sheet, row format, preview, or confirmation is specified, creating a plausible risk of modifying the wrong shared record or adding incorrect content. A user can restrict access to a named sheet and require row preview and destination confirmation before writing.

SKILL.md:36In the instructionsOpen original file
- Delegate email action items with `gws workflow +email-to-task`.- Track team OKRs in a shared Sheet with `gws sheets +append`.
Show 1 other places
SKILL.md:15In the instructionsOpen original file
        - gws-chat        - gws-drive        - gws-sheets---
Could it bypass safety checks?Looks for skipped website security checks, excessive file access, or actions that skip your approval.No risks found
Could it mislead the AI or hide text?Checks the skill instructions for requests to ignore you, influence the report, or hide text in invisible characters.No risks found
Could it change links or payment recipients without asking?Looks for forced referral or payment changes combined with instructions to hide the change.Risks found: 1
Medium risk

Email content can become delegated work without a visible human-confirmation step

Source references: 2
What we found

The Skill directs the `email-to-task` workflow to delegate action items from email. Email may be external, mistaken, or deceptive, while the visible instructions do not require verification of the sender, task wording, assignee, or deadline first.

Why this matters

A mistaken or malicious message could alter team assignments, create unapproved work, distort priorities, or direct work to an inappropriate person.

What this evidence establishes

The instruction does say to “delegate” email action items through `email-to-task`, which could affect task ownership or team decisions. However, the workflow implementation is absent, so the evidence does not establish whether it directly creates or assigns tasks or merely drafts suggestions. This fits the stated coordination purpose, but no verification or confirmation step is visible. A user can ask the author to document its write behavior and restrict it to drafts pending sender and assignee verification.

This assessment concerns the code and conditions shown, not proof that harm has occurred.
SKILL.md:35In the instructionsOpen original file
- Get weekly snapshots with `gws workflow +weekly-digest`.- Delegate email action items with `gws workflow +email-to-task`.- Track team OKRs in a shared Sheet with `gws sheets +append`.
Show 1 other places
SKILL.md:29In the instructionsOpen original file
- `gws workflow +weekly-digest`- `gws workflow +email-to-task`

Inside this skill

3 instruction sections

This Skill is a team-lead persona that depends on the `gws` tool with Calendar, Gmail, Chat, Drive, and Sheets capabilities, and exposes standup, meeting-preparation, weekly-digest, and email-to-task workflows.

View source
SKILL.md:8In the instructionsOpen original file
    category: "persona"    requires:      bins:        - gws      skills:        - gws-calendar        - gws-gmail        - gws-chat        - gws-drive        - gws-sheets---
SKILL.md:25In the instructionsOpen original file
## Relevant Workflows- `gws workflow +standup-report`- `gws workflow +meeting-prep`- `gws workflow +weekly-digest`- `gws workflow +email-to-task`

Sensitive-data handling is only presented as a tip to use `--sanitize`; the visible instructions do not say that it is applied by default to standups, email, digests, or Chat operations.

View source
SKILL.md:38In the instructionsOpen original file
## Tips- Use `gws calendar +agenda --week --format table` for weekly team calendar views.- Pipe standup reports to Chat with `gws chat spaces messages create`.- Use `--sanitize` for any operations involving sensitive team data.
Start here · InstructionsSKILL.md
persona-team-lead
Lines connect the instruction file to its sections, not an observed execution order. Select a section to read the source.
Files and check records1 files

Coverage and gaps

Content covered in each file

These are the source ranges included in this check, not a guarantee that every issue has been resolved.

  • SKILL.mdFull text included

This report is for the version above. We read the available code and instructions without running the skill or checking extra packages it installs. This is not a promise of safety: a different version or setup may behave differently.

  • SKILL.mdInstructions
Lines read
43
File checksum (to compare versions)
5d89e698b1d0d646ab92c74a85fb5ece181a89697fbccab24d047d9f3e661796