skills/cshen/skills/dida365/Gen Agent Trust Hub

dida365

Pass

Audited by Gen Agent Trust Hub on Mar 20, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection from task data retrieved via the Dida365 API.\n- Ingestion points: Task titles and notes are ingested into the agent context via the cmd_tasks function in tt.py.\n- Boundary markers: The SKILL.md file lacks boundary markers or instructions for the agent to isolate external task content from primary instructions.\n- Capability inventory: The agent can create, list, update, and delete tasks based on its interpretation of the retrieved content.\n- Sanitization: Content fetched from the API is displayed to the agent without filtering or validation for natural language instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 20, 2026, 05:40 PM