adhd-daily-planner
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill configuration defines a vulnerability surface for indirect prompt injection.
- Ingestion points: The allowed-tools list includes WebFetch and WebSearch, which allow the agent to read data from external websites.
- Boundary markers: The skill does not provide delimiters or instructions to treat web-fetched content as untrusted data.
- Capability inventory: The agent has access to Bash, Write, Edit, and Task tools, providing a path for system-level actions if untrusted data contains malicious instructions.
- Sanitization: No specific filtering or validation of external input is requested or implemented within the skill instructions.
Audit Metadata