todo
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill performs routine file management tasks on project-specific markdown files (
brain/todos.mdandbrain/archive/todos.md). It uses standard markdown formatting and does not access sensitive system paths, network resources, or external code. - [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted input in the form of task descriptions from the todo file. While it lacks explicit sanitization or boundary markers for these inputs, the potential impact is minimal as the skill's capabilities are restricted to local file modifications within the project directory.
- Ingestion points: Reads task descriptions and IDs from
brain/todos.md. - Boundary markers: Absent (uses markdown structure for delimitation).
- Capability inventory: Limited to file read and write operations via Edit/Write tools.
- Sanitization: Absent.
Audit Metadata