project-management-guru-adhd

Pass

Audited by Gen Agent Trust Hub on Mar 5, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection attack surface because it is authorized to ingest untrusted data from the internet and has the capability to write to the local filesystem.
  • Ingestion points: The skill is permitted to use WebFetch and mcp__firecrawl__firecrawl_search (defined in SKILL.md).
  • Boundary markers: There are no explicit instructions or delimiters defined to prevent the agent from following malicious instructions that might be embedded in fetched web content.
  • Capability inventory: The skill has access to file modification tools including Write, Edit, and TodoWrite (defined in SKILL.md).
  • Sanitization: No sanitization or validation mechanisms are specified for data retrieved from external web sources before it is processed or used in file operations.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 5, 2026, 12:41 PM