kanban-board
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill provides a template and instructions for generating a static Kanban board interface using HTML and CSS. No executable scripts, subprocesses, or network operations are present in the provided files.
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest data from an external
DESIGN.mdfile and a user-provided brief to populate the board's content. While this creates a surface for indirect prompt injection, the skill's functionality is limited to static UI generation, which does not allow for command execution or data exfiltration. - Ingestion points: Reads Squad name, sprint number, columns, and member roster from
DESIGN.mdand the user brief. - Boundary markers: None explicitly defined in the instructions.
- Capability inventory: Limited to generating static HTML artifacts. No network, file-write, or shell execution capabilities.
- Sanitization: No specific sanitization or escaping instructions are provided for the interpolated data.
Audit Metadata