boards-work-item-write

Pass

Audited by Gen Agent Trust Hub on Sep 30, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from external sources, specifically work item titles, descriptions, and comments retrieved from Azure DevOps.
  • Ingestion points: The skill performs GET requests to Azure DevOps API endpoints to retrieve existing work item data.
  • Boundary markers: The skill incorporates strong mitigations, including a mandatory "dry-run" (validateOnly=true) phase and a requirement for explicit user confirmation before any data is written or updated.
  • Capability inventory: The skill possesses network capabilities via curl and file-write access for temporary payload storage.
  • Sanitization: The instructions do not specify automated sanitization of retrieved HTML or Markdown content, relying on the user to review the changes during the confirmation step.
  • [DYNAMIC_EXECUTION]: The skill generates temporary files to handle complex data payloads in specific environments.
  • Evidence: For Windows PowerShell compatibility, the skill instructions state that the agent should write the JSON body to a temporary file (body.json) before sending it via curl.exe with the --data-binary flag.
  • [COMMAND_EXECUTION]: The skill relies on the execution of curl commands to interact with the Azure DevOps REST API.
  • Evidence: Multiple sections of SKILL.md provide shell command templates for interacting with dev.azure.com. These are legitimate and within the scope of the skill's primary purpose.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 30, 2026, 04:39 AM