coding-best-practices
Pass
Audited by Gen Agent Trust Hub on Oct 3, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to ingest and analyze external repository content, logs, and pull request feedback.
- Ingestion points: Repository code under review, diagnostic logs, reproduction environments, and pull request comments.
- Boundary markers: The instructions do not define specific delimiters or guidelines for the agent to separate untrusted data from its core operational logic.
- Capability inventory: The skill allows the agent to modify files (implementing fixes), execute repository-level checks and tests (shell commands), and interact with pull request management tools (network/API interaction).
- Sanitization: There are no requirements for validating or sanitizing external content before it is processed or used to generate outcomes.
Audit Metadata