boards-backlog-audit
Pass
Audited by Gen Agent Trust Hub on Sep 30, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data (titles, descriptions, and acceptance criteria) from Azure DevOps work items, creating a potential surface for indirect prompt injection.
- Ingestion points: Azure DevOps REST API responses in SKILL.md steps 4, 5, and 6.
- Boundary markers: None explicitly mentioned to separate work item content from agent instructions in the final output.
- Capability inventory: Shell command execution (curl) for reading data.
- Sanitization: The skill instructions mention stripping HTML tags and whitespace from the 'Acceptance Criteria' field.
- [COMMAND_EXECUTION]: The skill uses
curlto perform REST API requests. Commands are dynamically constructed using variables like project names, team names, and work item IDs. - [SAFE]: All network operations are restricted to well-known Microsoft Azure DevOps domains (dev.azure.com and visualstudio.com). Credentials are handled securely through environment variables, and the skill explicitly instructs the agent not to ask for or display the Personal Access Token (PAT).
Audit Metadata