calibrate-board-mutations

Pass

Audited by Gen Agent Trust Hub on Sep 5, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external project board data which could potentially contain untrusted content. Ingestion points: Step 1 (board data resolution) and Step 5 (post-execution item re-fetch). Boundary markers: Absent; data is parsed into a ledger but not explicitly delimited against prompt instructions. Capability inventory: Step 4 involves invoking the preflight-mutations workflow for board updates. Sanitization: Not explicitly implemented. This risk is mitigated by the requirement for explicit user approval of samples before processing (Step 3).
  • [SAFE]: The skill follows security best practices by including restrictive configuration in the frontmatter and agent policy, such as disabling implicit model invocation to prevent unauthorized execution.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 5, 2026, 09:35 AM
Security Audit — agent-trust-hub — calibrate-board-mutations