tasks-build
Pass
Audited by Gen Agent Trust Hub on Sep 19, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from an external source which could contain malicious instructions.
- Ingestion points: Fetches title, description, and linked page content from a user-provided Notion URL (SKILL.md).
- Boundary markers: The skill lacks explicit instructions to treat the fetched content as data only or to ignore embedded commands.
- Capability inventory: The agent is authorized to modify codebases ("implement the code changes") and update external task statuses based on the instructions found in the task.
- Sanitization: No sanitization or validation steps are defined for the content retrieved from the Notion API.
Audit Metadata