ai2human-task-router
Pass
Audited by Gen Agent Trust Hub on Sep 9, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes data returned by human executors, which is considered untrusted external input.
- Ingestion points: Human review notes, screenshot captions, and structured proof fields as described in
SKILL.md. - Boundary markers: The agent is required to provide a mandatory task preview and receive explicit user confirmation before creation.
- Capability inventory: The skill interacts with the AI2Human API via network requests.
- Sanitization: Instructions in
SKILL.mdandreferences/payment-policy.mdexplicitly mandate that the agent treat all human-provided data as untrusted and refrain from executing commands or links within that data. - [SAFE]: Credential management is handled securely through the use of environment variables and instructions to use approved secret managers, avoiding hardcoded secrets.
- [SAFE]: The provided diagnostic script (
scripts/smoke.mjs) includes security logic to prevent the transmission of API keys to untrusted remote hosts.
Audit Metadata