project-management-guru-adhd
Pass
Audited by Gen Agent Trust Hub on Mar 5, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection attack surface because it is authorized to ingest untrusted data from the internet and has the capability to write to the local filesystem.
- Ingestion points: The skill is permitted to use
WebFetchandmcp__firecrawl__firecrawl_search(defined inSKILL.md). - Boundary markers: There are no explicit instructions or delimiters defined to prevent the agent from following malicious instructions that might be embedded in fetched web content.
- Capability inventory: The skill has access to file modification tools including
Write,Edit, andTodoWrite(defined inSKILL.md). - Sanitization: No sanitization or validation mechanisms are specified for data retrieved from external web sources before it is processed or used in file operations.
Audit Metadata