coding-best-practices

Pass

Audited by Gen Agent Trust Hub on Oct 3, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to ingest and analyze external repository content, logs, and pull request feedback.
  • Ingestion points: Repository code under review, diagnostic logs, reproduction environments, and pull request comments.
  • Boundary markers: The instructions do not define specific delimiters or guidelines for the agent to separate untrusted data from its core operational logic.
  • Capability inventory: The skill allows the agent to modify files (implementing fixes), execute repository-level checks and tests (shell commands), and interact with pull request management tools (network/API interaction).
  • Sanitization: There are no requirements for validating or sanitizing external content before it is processed or used to generate outcomes.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 3, 2026, 08:23 PM