task-management

Pass

Audited by Gen Agent Trust Hub on Sep 20, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from external web pages which could be used to deliver malicious instructions.
  • Ingestion points: Web content is ingested via context_dev_scrape_markdown and context_dev_extract_structured_data tools as defined in references/sandbase-api-map.md.
  • Boundary markers: Absent. The skill lacks explicit delimiters or instructions to ignore embedded commands within scraped content.
  • Capability inventory: The skill has the ability to read and write to a local TASKS.md file and invoke external scraping tools.
  • Sanitization: Absent. There is no evidence of sanitization or validation of the data retrieved from external sources before it is processed.
  • [COMMAND_EXECUTION]: The skill uses a dynamic tool-invocation pattern to execute scraping functionality.
  • It employs sandbase_describe_tool and sandbase_call_tool to interact with context_dev_scrape_markdown and context_dev_extract_structured_data based on runtime-resolved schemas.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 20, 2026, 08:11 AM
Security Audit — agent-trust-hub — task-management