miro-reference-architecture

Pass

Audited by Gen Agent Trust Hub on Sep 10, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill implements strong security guidelines, explicitly forbidding the printing of credentials and sensitive data. It mandates the use of narrow scopes and encrypted storage for tokens.\n- [INDIRECT_PROMPT_INJECTION]: The skill uses repository inspection tools (Read, Glob, Grep) to analyze configuration and code. While this creates a surface for indirect prompt injection from untrusted files, the skill mitigates this by requiring explicit human confirmation, operator receipts, and approval-gated handoffs for any live execution or mutations.\n
  • Ingestion points: Repository inspection using Read, Glob, and Grep in SKILL.md\n
  • Boundary markers: Confirmation of requested mode in Tool Discipline section\n
  • Capability inventory: Write and Edit tools in SKILL.md\n
  • Sanitization: Manual review and approval gates for sensitive operations
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 10, 2026, 11:34 PM
Security Audit — agent-trust-hub — miro-reference-architecture