bugs-flow
Pass
Audited by Gen Agent Trust Hub on Mar 31, 2026
Risk Level: SAFE
Full Analysis
- [PROMPT_INJECTION]: The skill has an indirect prompt injection surface because it processes untrusted external data such as Sentry issue details, logs, and traces. While this is inherent to its bug-fixing purpose, the skill lacks explicit boundary markers for this data.
- Ingestion points: Evidence gathered from Sentry, logs, and repro steps (specified in SKILL.md and references/bug-doc-contract.md).
- Boundary markers: No specific delimiters are required for the ingested external data.
- Capability inventory: File system modification and code implementation capabilities in fix mode.
- Sanitization: No explicit sanitization or validation of ingested evidence is described.
Audit Metadata