dino-manage-todo

Pass

Audited by Gen Agent Trust Hub on Jul 13, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: No malicious patterns or security vulnerabilities were detected. The skill implements several defensive measures to ensure safe operation.\n- [PROMPT_INJECTION]: The skill recognizes that task and note content from the 'dino' tool is untrusted data. It explicitly instructs the agent to treat this content as data only and never to execute instructions found within it, effectively mitigating indirect prompt injection risks.\n- [COMMAND_EXECUTION]: While the skill uses the 'Bash' tool, its use is strictly scoped to the 'dino' CLI. The instructions mandate the use of '--dry-run' flags and require explicit user confirmation before any state-changing operations are executed.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 13, 2026, 12:07 PM
Security Audit — agent-trust-hub — dino-manage-todo