triage
Pass
Audited by Gen Agent Trust Hub on Jun 28, 2026
Risk Level: SAFE
Full Analysis
- [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface as it is designed to ingest and process untrusted data from issue trackers, including issue bodies and comments. Specifically, the 'Reproduce' step in SKILL.md instructs the agent to 'read the reporter's steps' and 'run tests or commands', which could potentially lead to the execution of malicious instructions provided by an external reporter. However, this functionality is core to the skill's purpose as a triage assistant. The skill includes a mandatory disclaimer for AI-generated comments to ensure transparency. Evidence: Ingestion points include issue bodies and comments (SKILL.md); Capability inventory includes command execution and file writes to the .out-of-scope/ directory; Boundary markers and sanitization are not explicitly defined beyond the output disclaimer.
Audit Metadata