file-todos
Warn
Audited by Gen Agent Trust Hub on Feb 15, 2026
Risk Level: MEDIUMPROMPT_INJECTION
Full Analysis
- Indirect Prompt Injection (MEDIUM): The skill instructs the agent to read and process markdown files that may contain untrusted content. * Ingestion points: Existing markdown files in the
todos/directory. * Boundary markers: Absent; the agent reads raw file content without delimiters. * Capability inventory: The agent can create and modify files in the repository. * Sanitization: No sanitization of the markdown content is specified.
Audit Metadata