skills/aelaguiz/arch_skill/bugs-flow/Gen Agent Trust Hub

bugs-flow

Pass

Audited by Gen Agent Trust Hub on Mar 31, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: The skill has an indirect prompt injection surface because it processes untrusted external data such as Sentry issue details, logs, and traces. While this is inherent to its bug-fixing purpose, the skill lacks explicit boundary markers for this data.
  • Ingestion points: Evidence gathered from Sentry, logs, and repro steps (specified in SKILL.md and references/bug-doc-contract.md).
  • Boundary markers: No specific delimiters are required for the ingested external data.
  • Capability inventory: File system modification and code implementation capabilities in fix mode.
  • Sanitization: No explicit sanitization or validation of ingested evidence is described.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 31, 2026, 08:16 AM
Security Audit — agent-trust-hub — bugs-flow