start

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • Indirect Prompt Injection Surface: The skill is designed to ingest and analyze data from various untrusted external sources, which could potentially contain malicious instructions intended to influence the agent's behavior.
  • Ingestion Points: The skill processes data from user-provided task lists (e.g., TASKS.md, Jira, Asana) and external MCP sources including chat messages, emails, documents, and calendars (Step 5 and Step 6).
  • Boundary Markers: There are no explicit instructions or delimiters defined to separate user data from the agent's primary instructions, nor are there directions to ignore embedded commands within the processed data.
  • Capability Inventory: The agent is granted the capability to write to the local filesystem, specifically creating and modifying files such as TASKS.md, CLAUDE.md, and project/profile files within the memory/ directory (Step 7).
  • Sanitization: The skill does not describe any specific sanitization, filtering, or validation processes for the content retrieved from external integrations before it is interpolated into the agent's context or written to persistent files.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 04:51 PM
Security Audit — agent-trust-hub — start