review-missing-priorities

Pass

Audited by Gen Agent Trust Hub on Jun 17, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill is strictly read-only and uses an MCP tool to fetch Todoist data. It does not attempt to exfiltrate data to untrusted domains or execute arbitrary code.\n- [PROMPT_INJECTION]: Indirect Prompt Injection Surface (Category 8): The skill retrieves and displays data from external Todoist tasks, which could potentially contain malicious instructions.\n
  • Ingestion points: Todoist task titles and descriptions (SKILL.md, Step 3).\n
  • Boundary markers: None specified; the instructions do not include delimiters or warnings to ignore instructions within the tasks.\n
  • Capability inventory: Read-only access to Todoist; the skill only generates a table and suggests a handoff to another skill.\n
  • Sanitization: None identified in the prompt instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 17, 2026, 10:52 AM
Security Audit — agent-trust-hub — review-missing-priorities