trello-automation
Pass
Audited by Gen Agent Trust Hub on Sep 10, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill instructions require the integration of an external MCP server at
https://rube.app/mcpto access Trello management tools. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to process data from Trello boards and cards, creating a vulnerability where malicious instructions embedded in card descriptions or comments could influence agent behavior.
- Ingestion points: Card content, titles, and comments retrieved via
TRELLO_GET_SEARCHandTRELLO_GET_BOARDS_CARDS_BY_ID_BOARD. - Boundary markers: None. The skill lacks instructions to delimit external card data from the agent's system instructions.
- Capability inventory: The skill provides extensive tools for card creation, list management, comment posting, and attachment handling.
- Sanitization: None. The skill does not instruct the agent to sanitize or validate card content before processing or acting upon it.
Audit Metadata