file-todos

Warn

Audited by Gen Agent Trust Hub on Feb 15, 2026

Risk Level: MEDIUMPROMPT_INJECTION
Full Analysis
  • Indirect Prompt Injection (MEDIUM): The skill instructs the agent to read and process markdown files that may contain untrusted content. * Ingestion points: Existing markdown files in the todos/ directory. * Boundary markers: Absent; the agent reads raw file content without delimiters. * Capability inventory: The agent can create and modify files in the repository. * Sanitization: No sanitization of the markdown content is specified.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Feb 15, 2026, 10:56 PM