investigate-before-recommend
Pass
Audited by Gen Agent Trust Hub on Jun 27, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to use standard CLI tools such as
gh repo cloneandmanus-mcp-clito interact with and verify the user's infrastructure. These actions are appropriate for the skill's stated goal of grounded architectural analysis.\n- [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it is designed to ingest and process data from external, potentially attacker-controlled sources.\n - Ingestion points: The agent is directed to read data from external sources including Supabase database tables, GitHub repository contents, and web-based admin dashboards (SKILL.md, references/investigation_checklist.md).\n
- Boundary markers: There are no explicit instructions or delimiters defined to separate user-provided data from system instructions, meaning instructions embedded in a README or database record could influence the agent.\n
- Capability inventory: The agent has the ability to execute shell commands and access the local file system while processing this external data.\n
- Sanitization: The protocol does not include steps for sanitizing, filtering, or validating the content retrieved from external environments before interpretation.
Audit Metadata