my-tasks

Pass

Audited by Gen Agent Trust Hub on Sep 13, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill fetches and renders content from an external source (ClickUp), which represents an untrusted data ingestion surface.
  • Ingestion points: Data is ingested through the clickup_search_tasks MCP tool as described in SKILL.md.
  • Boundary markers: The instructions do not define clear delimiters or use specific escaping techniques to isolate the task content from the agent's core instruction set.
  • Capability inventory: The skill's primary capability is reading and formatting data into a table; it does not explicitly request high-privilege capabilities such as file system writes or arbitrary command execution.
  • Sanitization: There is no explicit logic provided to sanitize or validate the content of the tasks before they are displayed to the user.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 13, 2026, 06:10 PM
Security Audit — agent-trust-hub — my-tasks