skills/saltbo/agent-kanban/ak-task/Gen Agent Trust Hub

ak-task

Pass

Audited by Gen Agent Trust Hub on May 9, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill extensively uses the Bash tool to execute commands for the ak (Agent Kanban) and gh (GitHub) CLIs. These commands manage task lifecycles, monitor agent processes, retrieve logs, and perform PR operations such as viewing diffs and merging.
  • [PROMPT_INJECTION]: The skill contains instructions that explicitly increase the agent's autonomy and operational persistence, such as "act immediately, do not ask the user" and "Workflow completion is mandatory... immediately resume the workflow from where you left off." These are functional instructions for the intended leader role and do not attempt to bypass core safety guardrails.
  • [INDIRECT_PROMPT_INJECTION]: The leader agent ingests data from external sources that could be influenced by other actors. Ingestion points include task notes provided by workers (ak get note), PR descriptions and diffs (gh pr view/diff), and repository documentation (CONTRIBUTING.md). There are no technical boundary markers or sanitization steps, but the skill mandates a multi-gate manual review process to evaluate the quality and appropriateness of these inputs.
  • [EXTERNAL_DOWNLOADS]: The skill references the installation of specialist worker skills, such as Playwright from Microsoft. These references are part of the intended multi-agent orchestration and involve well-known, trusted organizations.
Audit Metadata
Risk Level
SAFE
Analyzed
May 9, 2026, 12:03 PM