skills/intbot/skills/board/Gen Agent Trust Hub

board

Pass

Audited by Gen Agent Trust Hub on Jun 27, 2026

Risk Level: SAFE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from external project files to scaffold or sync the implementation board.
  • Ingestion points: internal/board.md, .claude/board.md, board.md, docs/board.md, and files matching TODO*, ROADMAP*, PLAN*, BACKLOG*, or README.
  • Boundary markers: Not present; the agent parses content directly.
  • Capability inventory: File reading, writing (with confirmation), and glob/grep across the project directory.
  • Sanitization: No explicit sanitization or filtering of external file content is described.
  • [COMMAND_EXECUTION]: The skill utilizes file system operations including globbing and grepping to discover task-related information in the codebase. This access is necessary for the tool's core functionality.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 27, 2026, 02:28 AM
Security Audit — agent-trust-hub — board