task-list

Pass

Audited by Gen Agent Trust Hub on Aug 22, 2026

Risk Level: SAFE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes user-supplied task descriptions, creating an ingestion point for untrusted data that is later reflected in the agent's context. 1. Ingestion points: content argument in add and add_multiple operations within scripts/tasks.py. 2. Boundary markers: Task items are formatted using markdown checkboxes and organized under status headers. 3. Capability inventory: The script is limited to reading and writing a todo.md file within the agent's workspace. 4. Sanitization: Basic whitespace stripping and delimiter splitting are applied to the input content.
  • [DATA_EXPOSURE_AND_EXFILTRATION]: The script accesses the file system to persist state, but it correctly restricts file operations to designated workspace paths defined by environment variables or a safe local fallback. No unauthorized data access or exfiltration patterns were observed.
  • [SAFE]: The skill, authored by NVIDIA, functions as a legitimate productivity tool with no evidence of malicious intent, obfuscation, or remote code execution. The file-based persistence is necessary for the skill's primary purpose.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 22, 2026, 12:40 PM
Security Audit — agent-trust-hub — task-list