one-list-work
Pass
Audited by Gen Agent Trust Hub on Jul 10, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill defines a set of tools (list-planned-work, list-completed-work, list-blockers, list-initiatives, list-bugs) designed to interact with the One Horizon MCP.
- [INDIRECT_PROMPT_INJECTION]: The skill processes data from an external source (One Horizon). While this creates a surface for indirect prompt injection if task titles or descriptions contain malicious instructions, the skill does not possess high-risk capabilities like arbitrary command execution or network exfiltration that would allow for successful exploitation.
- Ingestion points: Data fetched via One Horizon MCP tools in SKILL.md.
- Boundary markers: Not present.
- Capability inventory: No dangerous capabilities (subprocesses, file writes, or direct network calls) are present in the skill files.
- Sanitization: No specific sanitization or filtering logic is defined for the fetched data.
Audit Metadata