miro-enterprise-rbac
Pass
Audited by Gen Agent Trust Hub on Sep 10, 2026
Risk Level: SAFE
Full Analysis
- [CREDENTIALS_UNSAFE]: The skill includes explicit security instructions to never print access tokens, refresh tokens, client secrets, or authorization codes. It advocates for OAuth 2.0 with the narrowest possible scopes.
- [DATA_EXFILTRATION]: Instructions mandate the collection of minimum membership evidence using pseudonymized data and redacted evidence to prevent sensitive information exposure during the audit process.
- [INDIRECT_PROMPT_INJECTION]: The skill manages the risk of processing external Miro API data by requiring the classification of unknown access and maintaining clear approval boundaries for mutations.
- Ingestion points: Miro API response data processed during audits (SKILL.md).
- Boundary markers: Explicit output requirements to state what was not inspected or changed (SKILL.md).
- Capability inventory: File system access (Read, Glob, Grep, Write, Edit) and network access (WebFetch) (SKILL.md).
- Sanitization: Instructions to use redacted evidence and pseudonymized people (SKILL.md).
- [EXTERNAL_DOWNLOADS]: All external references target official Miro developer documentation (developers.miro.com), which are trusted sources for API reference material.
Audit Metadata