feature-close

Pass

Audited by Gen Agent Trust Hub on Sep 2, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill implements a workflow for feature closeout with a strong emphasis on manual verification and explicit confirmation.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests data from external sources including task records, feature records, and issue trackers.
  • Ingestion points: SKILL.md (Resolving the target, Audit completion sections).
  • Boundary markers: The instructions do not define specific delimiters for untrusted data, but they mandate strict human-in-the-loop confirmation for sensitive actions.
  • Capability inventory: Read repository files, interact with external trackers, manage Git branches and merge requests.
  • Sanitization: None explicitly defined, but the skill requires the agent to wait for specific user authorization naming the target resource, which mitigates automated execution of injected commands.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 2, 2026, 07:30 PM
Security Audit — agent-trust-hub — feature-close