project-management-guru-adhd
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill utilizes web-fetching tools which can ingest untrusted data into the agent's context. The lack of explicit boundary markers or sanitization instructions creates a potential attack surface for indirect prompt injection.
- Ingestion points: The skill's configuration in SKILL.md allows the use of mcp__firecrawl__firecrawl_search and WebFetch to retrieve information from external web sources.
- Boundary markers: The instructions do not define clear delimiters or "ignore embedded instructions" markers for the agent to use when processing external data.
- Capability inventory: The skill has access to file system tools including Read, Write, Edit, and TodoWrite, which could be exploited if malicious instructions are processed from the web.
- Sanitization: There are no explicit instructions within the skill or its reference files to sanitize or validate content retrieved via web tools before acting upon it or writing it to the filesystem.
Audit Metadata