trello-automation

Pass

Audited by Gen Agent Trust Hub on Jul 18, 2026

Risk Level: SAFENO_CODE
Full Analysis
  • [SAFE]: The skill is entirely instructional and does not include any executable scripts, binaries, or code files.
  • [EXTERNAL_DOWNLOADS]: The skill references the official Composio Rube MCP endpoint at https://rube.app/mcp. This is a well-known service for AI tool integrations and is considered safe.
  • [PROMPT_INJECTION]: The skill's functionality involves processing external data from Trello cards and comments, which represents a potential surface for indirect prompt injection. 1. Ingestion points: Data is retrieved from Trello via tools like TRELLO_GET_SEARCH and TRELLO_GET_BOARDS_CARDS_BY_ID_BOARD. 2. Boundary markers: No specific delimiters or safety instructions are provided to the agent to distinguish between data and instructions. 3. Capability inventory: The skill utilizes tools to create, update, and comment on Trello cards. 4. Sanitization: No explicit sanitization or validation of card content is described in the workflows.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 18, 2026, 04:24 PM
Security Audit — agent-trust-hub — trello-automation