skills/tobico/tobico-skills/to-tasks/Gen Agent Trust Hub

to-tasks

Pass

Audited by Gen Agent Trust Hub on Sep 9, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to execute specific shell commands using git and gh (GitHub CLI). These include git status, git add, git commit, and gh pr view to manage the lifecycle of a feature branch and its associated task files.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process external data such as roadmap briefs, project specifications, and codebase files. This creates a surface for indirect prompt injection where malicious instructions could be embedded in the analyzed documents, although the skill's capabilities are restricted to local file operations and standard version control actions.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 9, 2026, 07:28 AM
Security Audit — agent-trust-hub — to-tasks