The skill lacks proper input validation, allowing arbitrary string injection into project rules that can override legitimate architectural constraints and compromise the agent's operational integrity.
npx skills add https://github.com/zzhqqa478850-lang/project-blueprint-agentThe instruction to 'immediately save' any new architectural constraint via `--add-rule` allows the agent to persist arbitrary strings into the tool's state, which could be used to inject malicious constraints or override legitimate project rules.
YOU MUST immediately save it by running python -m project_blueprint --add-rule "<your_rule>"
Skill body contains no code blocks or usage examples, making it harder for users to evaluate.
Skill does not specify a license field. Specifying a license helps users understand usage terms.
[](https://mondoo.com/ai-agent-security/skills/github/zzhqqa478850-lang/project-blueprint-agent)<a href="https://mondoo.com/ai-agent-security/skills/github/zzhqqa478850-lang/project-blueprint-agent"><img src="https://mondoo.com/ai-agent-security/api/badge/github/zzhqqa478850-lang/project-blueprint-agent.svg" alt="Mondoo Skill Check" /></a>https://mondoo.com/ai-agent-security/api/badge/github/zzhqqa478850-lang/project-blueprint-agent.svgSkills can read files, run commands, and access credentials. Mondoo helps organizations manage the security risks of AI agent skills across their entire fleet.