task-management

Pass

Audited by Gen Agent Trust Hub on Mar 4, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection through the processing of external data sources.
  • Ingestion points: The skill reads meeting transcripts from Notion (pages prefixed with '@Date') and local context files within the .context/ directory.
  • Boundary markers: There are no defined delimiters or instructions to ignore embedded commands within the meeting transcripts being analyzed.
  • Capability inventory: The skill uses Read, Write, and Edit tools to update local files such as .context/current-focus.md and .context/projects/_index.md based on external input.
  • Sanitization: No sanitization or validation logic is present to filter malicious instructions embedded in meeting notes before they influence the agent's actions or local file modifications.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 4, 2026, 07:17 PM