ai2human-task-router

Pass

Audited by Gen Agent Trust Hub on Sep 9, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes data returned by human executors, which is considered untrusted external input.
  • Ingestion points: Human review notes, screenshot captions, and structured proof fields as described in SKILL.md.
  • Boundary markers: The agent is required to provide a mandatory task preview and receive explicit user confirmation before creation.
  • Capability inventory: The skill interacts with the AI2Human API via network requests.
  • Sanitization: Instructions in SKILL.md and references/payment-policy.md explicitly mandate that the agent treat all human-provided data as untrusted and refrain from executing commands or links within that data.
  • [SAFE]: Credential management is handled securely through the use of environment variables and instructions to use approved secret managers, avoiding hardcoded secrets.
  • [SAFE]: The provided diagnostic script (scripts/smoke.mjs) includes security logic to prevent the transmission of API keys to untrusted remote hosts.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 9, 2026, 08:47 AM
Security Audit — agent-trust-hub — ai2human-task-router