skills/poteto/noodle/todo/Gen Agent Trust Hub

todo

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill performs routine file management tasks on project-specific markdown files (brain/todos.md and brain/archive/todos.md). It uses standard markdown formatting and does not access sensitive system paths, network resources, or external code.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted input in the form of task descriptions from the todo file. While it lacks explicit sanitization or boundary markers for these inputs, the potential impact is minimal as the skill's capabilities are restricted to local file modifications within the project directory.
  • Ingestion points: Reads task descriptions and IDs from brain/todos.md.
  • Boundary markers: Absent (uses markdown structure for delimitation).
  • Capability inventory: Limited to file read and write operations via Edit/Write tools.
  • Sanitization: Absent.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 03:00 AM