miro-enterprise-rbac

Pass

Audited by Gen Agent Trust Hub on Sep 10, 2026

Risk Level: SAFE
Full Analysis
  • [CREDENTIALS_UNSAFE]: The skill includes explicit security instructions to never print access tokens, refresh tokens, client secrets, or authorization codes. It advocates for OAuth 2.0 with the narrowest possible scopes.
  • [DATA_EXFILTRATION]: Instructions mandate the collection of minimum membership evidence using pseudonymized data and redacted evidence to prevent sensitive information exposure during the audit process.
  • [INDIRECT_PROMPT_INJECTION]: The skill manages the risk of processing external Miro API data by requiring the classification of unknown access and maintaining clear approval boundaries for mutations.
  • Ingestion points: Miro API response data processed during audits (SKILL.md).
  • Boundary markers: Explicit output requirements to state what was not inspected or changed (SKILL.md).
  • Capability inventory: File system access (Read, Glob, Grep, Write, Edit) and network access (WebFetch) (SKILL.md).
  • Sanitization: Instructions to use redacted evidence and pseudonymized people (SKILL.md).
  • [EXTERNAL_DOWNLOADS]: All external references target official Miro developer documentation (developers.miro.com), which are trusted sources for API reference material.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 10, 2026, 11:34 PM
Security Audit — agent-trust-hub — miro-enterprise-rbac