factory-triage
Pass
Audited by Gen Agent Trust Hub on Aug 26, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill possesses an indirect prompt injection surface as it is designed to process untrusted content from GitHub issues.
- Ingestion points: Processes external GitHub issue content and local documentation files (docs/factory/CONTRACT.md, docs/factory/CHARTER.md).
- Boundary markers: No explicit instruction delimiters or warnings to ignore embedded instructions are present in the skill file.
- Capability inventory: Performs network write operations (GitHub labels) and local file system writes (QUEUE.md).
- Sanitization: No specific sanitization or filtering of external issue data is described.
Audit Metadata