skills/lstig/agents/task-work/Gen Agent Trust Hub

task-work

Pass

Audited by Gen Agent Trust Hub on Jul 8, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it executes tasks based on the content of Joplin notes without sufficient safety boundaries. 1. Ingestion points: The note body is read from Joplin in Step 1 and Step 3 using retrieval tools. 2. Boundary markers: There are no explicit markers or instructions to treat note content as data rather than instructions. 3. Capability inventory: The skill can update/create notes and manipulate the local filesystem/git state. 4. Sanitization: No validation or sanitization is performed on the checklist items retrieved from the notes.
  • [PROMPT_INJECTION]: The instructions contain behavior overrides that forbid the agent from using standard interactive communication tools, requiring all queries to be recorded within the notes and ending the session immediately upon blocking.
  • [COMMAND_EXECUTION]: The skill directs the agent to perform environment modifications, including changing the working directory and checking out branches, based on metadata and log entries found in external notes.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 8, 2026, 10:53 PM
Security Audit — agent-trust-hub — task-work