factory-status

Pass

Audited by Gen Agent Trust Hub on Aug 26, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests live data from GitHub labels and pull requests which are untrusted external sources. Malicious actors could place instructions within these fields to attempt to influence the agent's output or subsequent actions.
  • Ingestion points: Live GitHub labels, open pull requests, run records, gate health, and charter limits are processed by the skill.
  • Boundary markers: The skill definition does not include specific delimiters or instructions for the agent to ignore potentially malicious embedded content within the GitHub data.
  • Capability inventory: The skill is restricted to reporting only; it explicitly states it does not have the capability to merge, approve, label, or close work, which limits the potential impact of an injection.
  • Sanitization: There is no evidence of filtering, escaping, or validation of the content retrieved from GitHub before it is presented to the agent context.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 26, 2026, 11:40 PM
Security Audit — agent-trust-hub — factory-status