boards-work-item-write
Pass
Audited by Gen Agent Trust Hub on Sep 30, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from external sources, specifically work item titles, descriptions, and comments retrieved from Azure DevOps.
- Ingestion points: The skill performs
GETrequests to Azure DevOps API endpoints to retrieve existing work item data. - Boundary markers: The skill incorporates strong mitigations, including a mandatory "dry-run" (
validateOnly=true) phase and a requirement for explicit user confirmation before any data is written or updated. - Capability inventory: The skill possesses network capabilities via
curland file-write access for temporary payload storage. - Sanitization: The instructions do not specify automated sanitization of retrieved HTML or Markdown content, relying on the user to review the changes during the confirmation step.
- [DYNAMIC_EXECUTION]: The skill generates temporary files to handle complex data payloads in specific environments.
- Evidence: For Windows PowerShell compatibility, the skill instructions state that the agent should write the JSON body to a temporary file (
body.json) before sending it viacurl.exewith the--data-binaryflag. - [COMMAND_EXECUTION]: The skill relies on the execution of
curlcommands to interact with the Azure DevOps REST API. - Evidence: Multiple sections of
SKILL.mdprovide shell command templates for interacting withdev.azure.com. These are legitimate and within the scope of the skill's primary purpose.
Audit Metadata