adhd-daily-planner

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill configuration defines a vulnerability surface for indirect prompt injection.
  • Ingestion points: The allowed-tools list includes WebFetch and WebSearch, which allow the agent to read data from external websites.
  • Boundary markers: The skill does not provide delimiters or instructions to treat web-fetched content as untrusted data.
  • Capability inventory: The agent has access to Bash, Write, Edit, and Task tools, providing a path for system-level actions if untrusted data contains malicious instructions.
  • Sanitization: No specific filtering or validation of external input is requested or implemented within the skill instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 02:27 PM
Security Audit — agent-trust-hub — adhd-daily-planner