gsd-check-todos

Pass

Audited by Gen Agent Trust Hub on Apr 3, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill incorporates git commands as part of its legitimate workflow to maintain task state in a STATE.md file. This behavior is consistent with the stated purpose of a developer-focused automation tool.- [PROMPT_INJECTION]: The skill processes todo items from workspace files, creating an indirect prompt injection surface. While malicious content in a todo could theoretically influence agent behavior, the skill itself contains no injection instructions or safety bypasses and follows standard operational patterns.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 3, 2026, 04:33 AM