my-tasks
Pass
Audited by Gen Agent Trust Hub on Sep 13, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill fetches and renders content from an external source (ClickUp), which represents an untrusted data ingestion surface.
- Ingestion points: Data is ingested through the
clickup_search_tasksMCP tool as described in SKILL.md. - Boundary markers: The instructions do not define clear delimiters or use specific escaping techniques to isolate the task content from the agent's core instruction set.
- Capability inventory: The skill's primary capability is reading and formatting data into a table; it does not explicitly request high-privilege capabilities such as file system writes or arbitrary command execution.
- Sanitization: There is no explicit logic provided to sanitize or validate the content of the tasks before they are displayed to the user.
Audit Metadata