organvm-governance-pack
Pass
Audited by Gen Agent Trust Hub on Sep 27, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to analyze external repository content, which creates a potential surface for indirect prompt injection where malicious instructions could be embedded in the code or documentation of the repository being assessed.
- Ingestion points: The skill ingests untrusted data via the repository-to-assess input specified in SKILL.md.
- Boundary markers: The instructions do not define explicit boundary markers or provide the agent with guidance to ignore instructions found within the repository content.
- Capability inventory: The skill describes the orchestration of CLI tools including organvm ecosystem and organvm irf, and it automates code style enforcement using linters and pre-commit hooks as mentioned in SKILL.md.
- Sanitization: The skill does not mention any sanitization, filtering, or validation of the repository data before processing.
Audit Metadata