dino-manage-todo

Pass

Audited by Gen Agent Trust Hub on Jun 13, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: The skill explicitly instructs the agent to treat all task content and CLI output as untrusted data and forbids executing any instructions found within that data. This is a proactive defense against indirect prompt injection.
  • [COMMAND_EXECUTION]: Command execution is constrained to the dino utility. The workflow requires the use of --dry-run to preview changes and mandates explicit user confirmation before executing any commands that mutate data (append, create, update).
  • [CREDENTIALS_UNSAFE]: The skill follows security best practices for authentication by instructing users to manage tokens in their own terminal and explicitly warning against pasting sensitive authentication tokens into the conversation.
  • [DATA_EXFILTRATION]: No suspicious network operations or data exfiltration patterns were detected. The skill focuses on local CLI interactions for task management.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 13, 2026, 09:16 AM
Security Audit — agent-trust-hub — dino-manage-todo