gsd-check-todos
Pass
Audited by Gen Agent Trust Hub on Apr 3, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill incorporates git commands as part of its legitimate workflow to maintain task state in a STATE.md file. This behavior is consistent with the stated purpose of a developer-focused automation tool.- [PROMPT_INJECTION]: The skill processes todo items from workspace files, creating an indirect prompt injection surface. While malicious content in a todo could theoretically influence agent behavior, the skill itself contains no injection instructions or safety bypasses and follows standard operational patterns.
Audit Metadata