task-management
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill facilitates the ingestion of external and potentially untrusted data from Todoist, creating a vulnerability surface for indirect prompt injection.
- Ingestion points: The agent is instructed to read external content from Todoist via commands such as
todoist-cli list,todoist-cli today, andtodoist-cli showas described inSKILL.md. - Boundary markers: The instructions lack explicit delimiters or guidance to help the agent distinguish between its system instructions and data contained within task descriptions or comments.
- Capability inventory: The agent has permissions to modify, complete, and delete tasks. Crucially, the instructions explicitly advise the agent to "do it instead of tasking it" when possible, which could lead the agent to execute malicious instructions embedded in a task description.
- Sanitization: There are no mentioned mechanisms for sanitizing or validating data retrieved from the Todoist API before it is processed by the agent.
Audit Metadata