external-feedback-triage
Pass
Audited by Gen Agent Trust Hub on Sep 21, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONNO_CODE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to process untrusted data from external sources, creating a potential surface for indirect prompt injection.
- Ingestion points: External technical feedback, scanner results, blog advice, and model suggestions identified in
SKILL.md. - Boundary markers: The instructions require the agent to restate feedback in neutral technical terms and perform a triage loop to isolate the external claim from the current task context.
- Capability inventory: No command execution, network requests, or file-writing tools are defined in either
SKILL.mdorreferences/review-feedback.md. - Sanitization: The skill mandates the use of an 'evidence-before-claims' verification step and cross-referencing suggestions against local configuration and evidence before acceptance.
- [NO_CODE]: The skill consists purely of Markdown instructions and reference tables; no executable scripts or system commands are provided.
Audit Metadata