factory-triage

Pass

Audited by Gen Agent Trust Hub on Aug 26, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill possesses an indirect prompt injection surface as it is designed to process untrusted content from GitHub issues.
  • Ingestion points: Processes external GitHub issue content and local documentation files (docs/factory/CONTRACT.md, docs/factory/CHARTER.md).
  • Boundary markers: No explicit instruction delimiters or warnings to ignore embedded instructions are present in the skill file.
  • Capability inventory: Performs network write operations (GitHub labels) and local file system writes (QUEUE.md).
  • Sanitization: No specific sanitization or filtering of external issue data is described.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 26, 2026, 11:41 PM
Security Audit — agent-trust-hub — factory-triage