miro-webhooks-events
Pass
Audited by Gen Agent Trust Hub on Sep 10, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests data from external Miro documentation and the local filesystem, establishing an attack surface for data-driven instructions.\n
- Ingestion points:
WebFetchtool fordevelopers.miro.comandRead,Glob,Grepfor repository files.\n - Boundary markers: The skill includes strong negative constraints against printing secrets and limits
WebFetchto official Miro domains.\n - Capability inventory:
WriteandEdittools permit modifying the codebase based on external documentation.\n - Sanitization: No automated filtering or sanitization is specified for fetched documentation content.\n- [EXTERNAL_DOWNLOADS]: Retrieves reference content from Miro's official developer portal.\n
- Evidence: The skill references official changelogs and documentation at
developers.miro.comusing theWebFetchtool.
Audit Metadata