miro-data-handling
Pass
Audited by Gen Agent Trust Hub on Sep 10, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill contains strong defensive instructions, requiring the agent to assume all board content is sensitive and to implement redaction and pseudonymization. It explicitly prohibits logging credentials or board content.
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to handle Miro board content which is untrusted data, creating an indirect prompt injection surface. The risk is mitigated by explicit instructions for data minimization and mandatory privacy/security approvals for data persistence or transmission. Ingestion points: Miro board content and metadata referenced in the repository or fetched documentation. Boundary markers: The skill relies on redaction and purpose-based mapping rather than specific prompt delimiters. Capability inventory: The skill uses Write, Edit, and WebFetch tools for documentation and repository management. Sanitization: Includes detailed requirements for pseudonymization and content redaction before logging or diagnostic export.
Audit Metadata