miro-security-basics
Pass
Audited by Gen Agent Trust Hub on Sep 10, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill analyzes external data (repository code and configuration) to perform security audits, creating a theoretical surface where malicious instructions embedded in source code could influence the agent's behavior.
- Ingestion points:
SKILL.mdusesRead,Glob, andGrepto inspect files within a user's repository. - Boundary markers: The instructions emphasize using evidence to make decisions explicit and reviewable, and requiring approval-gated handoffs for live execution.
- Capability inventory: The skill utilizes file system tools (
Read,Glob,Grep,Write,Edit) and network tools (WebFetch). - Sanitization: Explicit instructions are provided to redact credentials, tokens, and board content from telemetry and logs.
- [EXTERNAL_DOWNLOADS]: The skill references and fetches documentation from Miro's official developer portal (
developers.miro.com), which is a well-known service.
Audit Metadata