task-generation

Pass

Audited by Gen Agent Trust Hub on Mar 18, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: No evidence of malicious code, data exfiltration, or unauthorized command execution was found within the skill's instructions. All logic is focused on task formatting and organizational structure.\n- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process external Product Requirements Documents (PRDs), which presents a potential vulnerability surface.\n
  • Ingestion points: Processes potentially untrusted external text from PRDs to generate tasks (referenced throughout SKILL.md).\n
  • Boundary markers: Absent; there are no instructions to use delimiters or ignore embedded commands within the input PRDs.\n
  • Capability inventory: The instructions recommend utilizing the agent-browser skill for verification tasks (noted in the Quality Assurance section of SKILL.md).\n
  • Sanitization: Absent; the skill does not define methods to sanitize or validate PRD content before the agent acts upon it.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 18, 2026, 02:41 AM
Security Audit — agent-trust-hub — task-generation