task-list
Pass
Audited by Gen Agent Trust Hub on Aug 22, 2026
Risk Level: SAFE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes user-supplied task descriptions, creating an ingestion point for untrusted data that is later reflected in the agent's context. 1. Ingestion points: content argument in add and add_multiple operations within scripts/tasks.py. 2. Boundary markers: Task items are formatted using markdown checkboxes and organized under status headers. 3. Capability inventory: The script is limited to reading and writing a todo.md file within the agent's workspace. 4. Sanitization: Basic whitespace stripping and delimiter splitting are applied to the input content.
- [DATA_EXPOSURE_AND_EXFILTRATION]: The script accesses the file system to persist state, but it correctly restricts file operations to designated workspace paths defined by environment variables or a safe local fallback. No unauthorized data access or exfiltration patterns were observed.
- [SAFE]: The skill, authored by NVIDIA, functions as a legitimate productivity tool with no evidence of malicious intent, obfuscation, or remote code execution. The file-based persistence is necessary for the skill's primary purpose.
Audit Metadata