Productboard Automation

Pass

Audited by Gen Agent Trust Hub on Mar 29, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: The skill manages untrusted data from external sources (Productboard), which introduces a surface for indirect prompt injection.
  • Ingestion points: Data enters the agent context via PRODUCTBOARD_LIST_NOTES and PRODUCTBOARD_RETRIEVE_FEATURE in SKILL.md.
  • Boundary markers: Absent; there are no specific instructions to use delimiters or ignore embedded commands in the processed data.
  • Capability inventory: The skill has write capabilities including PRODUCTBOARD_CREATE_NOTE and PRODUCTBOARD_CREATE_NOTE_LINK in SKILL.md.
  • Sanitization: Absent; the instructions do not define validation or escaping for the external content.
  • [EXTERNAL_DOWNLOADS]: The skill requires connecting to a remote Model Context Protocol (MCP) server at https://rube.app/mcp. This connection is the standard mechanism for the skill's functionality and is provided by the development platform.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 29, 2026, 05:35 AM