miro-security-basics

Pass

Audited by Gen Agent Trust Hub on Sep 10, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill analyzes external data (repository code and configuration) to perform security audits, creating a theoretical surface where malicious instructions embedded in source code could influence the agent's behavior.
  • Ingestion points: SKILL.md uses Read, Glob, and Grep to inspect files within a user's repository.
  • Boundary markers: The instructions emphasize using evidence to make decisions explicit and reviewable, and requiring approval-gated handoffs for live execution.
  • Capability inventory: The skill utilizes file system tools (Read, Glob, Grep, Write, Edit) and network tools (WebFetch).
  • Sanitization: Explicit instructions are provided to redact credentials, tokens, and board content from telemetry and logs.
  • [EXTERNAL_DOWNLOADS]: The skill references and fetches documentation from Miro's official developer portal (developers.miro.com), which is a well-known service.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 10, 2026, 11:34 PM
Security Audit — agent-trust-hub — miro-security-basics