task-polling
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes task descriptions from a local file (
docs/task.md) and instructs the agent to execute them, which creates a surface where instructions within the task file could influence agent behavior. - Ingestion points: The agent reads tasks directly from
docs/task.md. - Boundary markers: The skill instructions do not provide explicit delimiters or warnings for the agent to ignore instructions embedded within the task descriptions.
- Capability inventory: The agent is prompted to execute actions found in the task descriptions, leveraging its general tool-use capabilities.
- Sanitization: No sanitization is performed on the natural language content of the tasks.
- [SAFE]: The included Python utility script is dedicated to local text processing of the task document. It uses standard libraries for JSON and regex, and employs atomic write operations via temporary files to ensure file integrity. No network activity, shell execution, or sensitive data access beyond the specific task file is present in the skill code.
Audit Metadata