calibrate-board-mutations
Pass
Audited by Gen Agent Trust Hub on Sep 5, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes external project board data which could potentially contain untrusted content. Ingestion points: Step 1 (board data resolution) and Step 5 (post-execution item re-fetch). Boundary markers: Absent; data is parsed into a ledger but not explicitly delimited against prompt instructions. Capability inventory: Step 4 involves invoking the preflight-mutations workflow for board updates. Sanitization: Not explicitly implemented. This risk is mitigated by the requirement for explicit user approval of samples before processing (Step 3).
- [SAFE]: The skill follows security best practices by including restrictive configuration in the frontmatter and agent policy, such as disabling implicit model invocation to prevent unauthorized execution.
Audit Metadata