factory-implement

Pass

Audited by Gen Agent Trust Hub on Aug 26, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted content from GitHub issues and project documentation which could contain malicious instructions designed to override agent behavior.
  • Ingestion points: The agent is instructed to read docs/factory/CONTRACT.md, docs/factory/CHARTER.md, and the content of "ready GitHub issues".
  • Boundary markers: No explicit delimiters or instructions to ignore embedded commands are provided for these external inputs.
  • Capability inventory: The skill allows the agent to "run fail-closed gates" (executing testing scripts), "obtain independent verification" (invoking subagents), and "open a draft pull request" (modifying the source code repository).
  • Sanitization: There is no mention of filtering, validation, or escaping logic for the content retrieved from GitHub issues.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 26, 2026, 11:40 PM
Security Audit — agent-trust-hub — factory-implement