kanban-board

Pass

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill provides a template and instructions for generating a static Kanban board interface using HTML and CSS. No executable scripts, subprocesses, or network operations are present in the provided files.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest data from an external DESIGN.md file and a user-provided brief to populate the board's content. While this creates a surface for indirect prompt injection, the skill's functionality is limited to static UI generation, which does not allow for command execution or data exfiltration.
  • Ingestion points: Reads Squad name, sprint number, columns, and member roster from DESIGN.md and the user brief.
  • Boundary markers: None explicitly defined in the instructions.
  • Capability inventory: Limited to generating static HTML artifacts. No network, file-write, or shell execution capabilities.
  • Sanitization: No specific sanitization or escaping instructions are provided for the interpolated data.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 23, 2026, 06:47 AM
Security Audit — agent-trust-hub — kanban-board