scratch
Pass
Audited by Gen Agent Trust Hub on Apr 2, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill manages session-scoped notes using standard task management tools (
TaskCreate,TaskList,TaskUpdate,TaskGet) to maintain an in-memory storage of thoughts. - [SAFE]: No external network communication, file system access outside of the provided task API, or credential handling was detected in the instructions or command definitions.
- [SAFE]: The capture of user-provided text for scratchpad notes (SKILL.md) represents a limited attack surface for indirect prompt injection; however, the skill's instructions to store content verbatim and avoid commentary effectively isolate the data from the agent's reasoning process. Capability inventory is limited to task management, and while explicit boundary markers or sanitization are absent, the restricted scope of tool access and the instruction to resume prior conversation immediately mitigate the risk of malicious payload execution.
Audit Metadata